CVE-2024-7143: Pulpcore: rbac permissions incorrectly assigned in tasks that create objects

Published Jul 26, 2024
·
Updated

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the AutoAddObjPermsMixin (typically the addrolesforobjectcreator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.

Other sources

When an RBAC object in Pulp is set to assign perms on its creation it uses the AutoAddObjPermsMixin, typically the method addrolesforobjectcreator. This method finds the object creator by checking the current authenticated user. For objects that are created within a task this current user is set by the first user with any perms on the task object. This means the oldest user with model/domain-level task perms will always be set to the current user of a task even if they didn't dispatch the task. Thus all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.

Red Hat

Affected Software

5 affected components
pip/pulpcore<=3.56.0
Pulpproject Pulp
All of the following
Pulpproject Pulp
redhat Ansible Automation Platform=2.0
IBM Concert Software<=1.0.0-1.1.0

Event History

Jul 26, 2024
Data Sourced
via Red Hat·07:05 PM
DescriptionSeverityAffected Software
Aug 7, 2024
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-7143?

CVE-2024-7143 has been classified as a critical vulnerability due to its potential for unauthorized access via role-based access control misconfigurations.

2

How do I fix CVE-2024-7143?

To mitigate CVE-2024-7143, upgrade the pulpcore package to a version higher than 3.56.0 which addresses this vulnerability.

3

Which versions of pulpcore are affected by CVE-2024-7143?

CVE-2024-7143 affects pulpcore versions up to and including 3.56.0.

4

What software components are impacted by CVE-2024-7143?

CVE-2024-7143 impacts the Pulp project implementations that utilize role-based access control.

5

Is Red Hat's Ansible Automation Platform vulnerable to CVE-2024-7143?

No, Red Hat's Ansible Automation Platform version 2.0 is not vulnerable to CVE-2024-7143.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203