CVE-2012-5509

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
12/03/2013
Last modified:
13/02/2023

Description

aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:cloudforms_cloud_engine:*:*:*:*:*:*:*:* 1.1 (including)
cpe:2.3:a:redhat:cloudforms_cloud_engine:1.0:*:*:*:*:*:*:*