Unrated severityNVD Advisory· Published Mar 12, 2013· Updated Jun 16, 2026
CVE-2012-6117
CVE-2012-6117
Description
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:redhat:cloudforms_cloud_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:cloudforms_cloud_engine:*:*:*:*:*:*:*:*range: <=1.1
- cpe:2.3:a:redhat:cloudforms_cloud_engine:1.0:*:*:*:*:*:*:*
- Range: <1.1.2
Patches
Vulnerability mechanics
References
2- bugzilla.redhat.com/show_bug.cginvdExploit
- rhn.redhat.com/errata/RHSA-2013-0545.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.