Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aaron Weitekamp

Researcher fromRed Hat
#52206of 53,632
4.2Total CVSS
Vulnerabilities · 2
Low
2
PT-2013-1801
2.1
2013-03-12
Red Hat · Aeolus Configuration Server · CVE-2012-5509
**Name of the Vulnerable Software and Affected Versions** Aeolus Configuration Server versions prior to 1.1.2 **Description** The issue concerns the aeolus-configserver-setup in the Aeolus Configuration Server, which is used in Red Hat CloudForms Cloud Engine. It uses world-readable permissions for a temporary file in /tmp. This allows local users to read credentials by accessing this file. **Recommendations** For versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary files in /tmp to minimize the risk of credential exposure.
PT-2013-1902
2.1
2013-03-12
Red Hat · Aeolus Configuration Server · CVE-2012-6117
**Name of the Vulnerable Software and Affected Versions** Aeolus Configuration Server versions prior to 1.1.2 **Description** The issue allows local users to read plaintext passwords by accessing the log file due to world-readable permissions. **Recommendations** For versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider changing the permissions of the /var/log/aeolus-configserver/configserver.log file to restrict access.