First published: Wed Jul 15 2015(Updated: )
It is reported by Austin Macdonald that pulp fails to properly remove existing permissions when an object is deleted (e.g. a user account), if an object with the same name is later created it will inherit the previous permissions leading to a potential privilege escalation. Please note that due to the manner in which pulp is used in Satellite6 it is not vulnerable.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pulpcore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5153 is categorized as a medium severity vulnerability.
To fix CVE-2015-5153, ensure you apply the latest patches provided by the Pulp project.
CVE-2015-5153 allows an attacker to potentially escalate privileges due to improper permissions being retained after object deletion.
CVE-2015-5153 affects all versions of Pulp prior to the fix for this vulnerability.
If you cannot apply the fix for CVE-2015-5153 immediately, limit the creation of objects with existing names and monitor access logs for any anomalies.