CVE-2012-6119: Candlepinproject Candlepin

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

Affected products

  • Candlepinproject Candlepin: up to and including 0.7.2; version 0.4.5 only; version 0.4.11 only; version 0.4.27 only; version 0.5.5 only; version 0.6.3 only
  • Red Hat Subscription Asset Manager: up to and including 1.2.0; version 1.0.0 only; version 1.1.0 only

Published 2013-04-02. Last modified 2026-06-16.