Pulp in Red Hat CloudForms prior to 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.
Synopsis
Important: CloudForms System Engine 11 update
Type/Severity
Security Advisory: Important
Topic
Updated CloudForms System Engine packages that fix multiple securityissues, several bugs, and add enhancements are now availableThe Red Hat Security Response Team has rated this update as havingimportan ...