CVE-2012-5509: Red Hat Cloudforms Cloud Engine

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.

Affected products

  • Red Hat Cloudforms Cloud Engine: up to and including 1.1; version 1.0 only

Published 2013-03-12. Last modified 2026-06-16.