First published: Wed Apr 10 2013(Updated: )
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack Essex | ||
Red Hat OpenStack Folsom |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-6120 is considered medium due to its potential for information disclosure.
To fix CVE-2012-6120, you should change the permissions of the /var/log/puppet directory to restrict access.
CVE-2012-6120 affects Red Hat OpenStack Essex and Folsom.
CVE-2012-6120 can allow local users to access sensitive Puppet log files.
CVE-2012-6120 is a local vulnerability that requires access to the affected system.