Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Cloudforms Cloud Engine
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-5509 1 Redhat 1 Cloudforms Cloud Engine 2023-12-10 2.1 LOW N/A
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.
CVE-2012-6117 1 Redhat 1 Cloudforms Cloud Engine 2023-12-10 2.1 LOW N/A
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.