CVE-2015-3229: Fedoraproject Spin-Kickstarts

Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.

fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.

Affected products

Published 2017-10-16. Last modified 2026-06-17.