CVE Vulnerabilities

CVE-2012-6118

Published: Mar 12, 2013 | Modified: Mar 18, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
5.5 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V3
Ubuntu

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.

Affected Software

Name Vendor Start Version End Version
Aeolus_conductor Redhat - (including) - (including)
CloudForms for RHEL 6 RedHat aeolus-conductor-0:0.13.26-1.el6cf *
CloudForms for RHEL 6 RedHat aeolus-configserver-0:0.4.12-3.el6cf *
CloudForms for RHEL 6 RedHat imagefactory-0:1.0.3-1.el6cf *
CloudForms for RHEL 6 RedHat oz-0:0.8.0-8.el6cf *

References