CVE-2015-5187: Infoleak

Published Aug 10, 2015
·
Updated

Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.

Other sources

John Sefler of Red Hat reports:

Under heavy load Candlepin may experience timeouts resulting in Java exception errors that can contain sensitive information. This only affects sites using candlepin with extremely heavy loads, as such Satellite 6 and SAM 1 are not affected.

Red Hat

Affected Software

1 affected component
Candlepinproject Candlepin

Event History

Aug 10, 2015
Data Sourced
08:01 PM
DescriptionSeverityAffected Software
Jul 25, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2015-5187?

CVE-2015-5187 has been classified as a medium severity vulnerability.

2

How do I fix CVE-2015-5187?

To fix CVE-2015-5187, it is recommended to monitor and control web traffic to reduce load and prevent timeouts.

3

What type of information can be leaked from CVE-2015-5187?

CVE-2015-5187 can leak sensitive information through Java exception statements generated during heavy traffic.

4

Which versions of Candlepin are affected by CVE-2015-5187?

CVE-2015-5187 affects all versions of Candlepin that are deployed.

5

Is there a workaround for CVE-2015-5187?

A suggested workaround for CVE-2015-5187 is to implement rate limiting on requests to the Candlepin service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203