Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1243526 | issue tracking vdb entry third party advisory |