CVE-2012-6117: Red Hat Cloudforms Cloud Engine

Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

Affected products

  • Red Hat Cloudforms Cloud Engine: up to and including 1.1; version 1.0 only

Published 2013-03-12. Last modified 2026-06-16.