Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat CloudForms 权限许可和访问控制问题漏洞
Vulnerability Description
Red Hat CloudForms是美国红帽(Red Hat)公司的一套混合基础架构管理平台。该平台可跨越虚拟机、云、容器和物理基础架构,为用户提供部署、管理等功能。 Red Hat CloudForms 1.1.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于/tmp目录下的临时文件使用全局可读权限。通过读取文件,本地攻击者利用该漏洞读取任意凭证。
CVSS Information
N/A
Vulnerability Type
N/A