Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-6117

Опубликовано: 01 нояб. 2012
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=906201Configserver: Passwords from application blueprint stored plaintext in configserver.log

EPSS

Процентиль: 39%
0.00474
Низкий

2.1 Low

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

github
около 4 лет назад

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

EPSS

Процентиль: 39%
0.00474
Низкий

2.1 Low

CVSS2