CVE-2012-6117
12.03.2013, 22:55
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | cloudforms_cloud_engine | 𝑥 ≤ 1.1 |
redhat | cloudforms_cloud_engine | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration