Redhat Subscription-Manager vulnerabilities

3 known vulnerabilities affecting redhat/subscription-manager.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-3899HIGHCVSS 7.8fixed in 1.28.39≥ 1.29.0, < 1.29.372023-08-23
CVE-2023-3899 [HIGH] CWE-285 CVE-2023-3899: A vulnerability was found in subscription-manager that allows local privilege escalation due to inad A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper
nvd
CVE-2017-2663HIGHCVSS 7.8fixed in 1.19.42018-07-27
CVE-2017-2663 [HIGH] CWE-270 CVE-2017-2663: It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access t It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.
nvd
CVE-2016-4455LOWCVSS 3.3≤ 1.17.6-12017-04-14
CVE-2016-4455 [LOW] CWE-264 CVE-2016-4455: The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.
nvd