CVE-2012-5509: Red Hat Cloudforms Cloud Engine
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.
Affected products
- Red Hat Cloudforms Cloud Engine: up to and including 1.1; version 1.0 only
Published 2013-03-12. Last modified 2026-06-16.