First published: Sat Nov 10 2012(Updated: )
Aaron Weitekamp of Red Hat reports: Description of problem: aeolus-configserver-setup leaves /tmp file that contains key/secret credentials. File is chmod 755. Version-Release number of selected component (if applicable): 1.1 [root@10-16-120-239 ~]# rpm -qa |grep aeolus aeolus-audrey-agent-0.4.10-1.el6cf.noarch aeolus-configserver-0.4.11-1.el6cf.noarch How reproducible: always Steps to Reproduce: 1. run `aeolus-configserver-setup` 2. search for file in /tmp `ls -ltr /tmp` Actual results: file /tmp/tmp.[random_string] exists with credentials Expected results: remove /tmp file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms Cloud Engine | <=1.1 | |
Redhat Cloudforms Cloud Engine | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.