CVE-2023-1832Improper Access Control in Candlepin

Severity
8.1HIGHNVD
CNA6.8
EPSS
0.1%
top 69.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateDec 24

Description

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
OSV
af_unix: Fix data-race around unix_tot_inflight.2025-12-24
GHSA
GHSA-4pcg-gfm2-cvg4: An improper access control flaw was found in Candlepin2023-10-04
CVEList
Improper authorization check in the server component2023-10-04

💥Exploits & PoCs

1
Exploit-DB
MyBB 1.8.32 - Remote Code Execution (RCE) (Authenticated)2023-04-03

📋Vendor Advisories

1
Red Hat
candlepin: Improper authorization check in the server component2023-08-14

🕵️Threat Intelligence

1
Wiz
CVE-2023-54006 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2023-1832 — Improper Access Control in Candlepin | cvebase