CVE-2012-4574 describes a local information disclosure vulnerability in Red Hat CloudForms before version 1.1, where the pulp.conf file had world-readable permissions. This allowed local users to read the administrative password, posing a low-severity risk with a CVSS score of 2.1. While the vulnerability grants access to sensitive credentials, it requires local access and has no known public exploits, Metasploit modules, or significant community discussion, indicating a low exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:redhat:cloudforms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.