CVE-2012-6120: Low severity red hat openstack essex vulnerability
Published Apr 10, 2013
·Updated
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
Affected Software
2 affected components
redhat OpenStack Essex
redhat Openstack Folsom
Event History
Apr 10, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6120?
The severity of CVE-2012-6120 is considered medium due to its potential for information disclosure.
2
How do I fix CVE-2012-6120?
To fix CVE-2012-6120, you should change the permissions of the /var/log/puppet directory to restrict access.
3
Which versions of Red Hat OpenStack are affected by CVE-2012-6120?
CVE-2012-6120 affects Red Hat OpenStack Essex and Folsom.
4
What type of information can be exposed due to CVE-2012-6120?
CVE-2012-6120 can allow local users to access sensitive Puppet log files.
5
Is CVE-2012-6120 a local or remote vulnerability?
CVE-2012-6120 is a local vulnerability that requires access to the affected system.