| CVE ID | Publié | Description | Score | Gravité | 
|---|---|---|---|---|
| An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant. | 8.1  | 
                                Haute  | 
                            ||
| Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests. | 2.1  |