CVE-2018-1090: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
Affected products
- Fedoraproject Fedora: affected versions not specified
- Pulpproject Pulp: before 2.16.2 (fixed in 2.16.2)
- Red Hat Satellite: version 6.4 only
Published 2018-06-18. Last modified 2026-06-17.