CVE-2012-6117
12.03.2013, 22:55
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | cloudforms_cloud_engine | 𝑥 ≤ 1.1 |
| redhat | cloudforms_cloud_engine | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration