CVE-2012-6117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
12/03/2013
Last modified:
11/04/2025

Description

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:cloudforms_cloud_engine:*:*:*:*:*:*:*:* 1.1 (including)
cpe:2.3:a:redhat:cloudforms_cloud_engine:1.0:*:*:*:*:*:*:*