Grinder in Red Hat CloudForms prior to 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.
Synopsis
Important: CloudForms System Engine 11 update
Type/Severity
Security Advisory: Important
Topic
Updated CloudForms System Engine packages that fix multiple securityissues, several bugs, and add enhancements are now availableThe Red Hat Security Response Team has rated this update as havingimportan ...