CVE-2023-1832: Candlepinproject Candlepin
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
Affected products
- Candlepinproject Candlepin: before 4.3.7-3 (fixed in 4.3.7-3)
- Red Hat Satellite: version 6.0 only
Published 2023-10-04. Last modified 2026-06-17.