Show plain JSON{"acknowledgement": "This issue was discovered by Dominic Cleal and James Laska (Red Hat).", "affected_release": [{"advisory": "RHSA-2013:0547", "cpe": "cpe:/a:cloudforms_systemengine:1::el6", "package": "candlepin-0:0.7.19-3.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2013-02-21T00:00:00Z"}, {"advisory": "RHSA-2013:0547", "cpe": "cpe:/a:cloudforms_systemengine:1::el6", "package": "katello-0:1.1.12.2-5.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2013-02-21T00:00:00Z"}, {"advisory": "RHSA-2013:0547", "cpe": "cpe:/a:cloudforms_systemengine:1::el6", "package": "katello-cli-0:1.1.8-14.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2013-02-21T00:00:00Z"}, {"advisory": "RHSA-2013:0547", "cpe": "cpe:/a:cloudforms_systemengine:1::el6", "package": "katello-configure-0:1.1.9-13.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2013-02-21T00:00:00Z"}, {"advisory": "RHSA-2013:0547", "cpe": "cpe:/a:cloudforms_systemengine:1::el6", "package": "katello-selinux-0:1.1.1-5.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2013-02-21T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "candlepin-0:0.7.24-1.el6_3", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "katello-0:1.2.1.1-1h.el6_4", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "katello-configure-0:1.2.3.1-4h.el6_4", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-actionpack-1:3.0.10-12.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-activemodel-0:3.0.10-3.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-delayed_job-0:2.1.4-3.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-json-0:1.7.3-2.el6_3", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-rack-1:1.3.0-4.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-rails_warden-0:0.5.5-2.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-rdoc-0:3.8-6.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "thumbslug-0:0.0.28.1-1.el6_4", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}], "bugzilla": {"description": "Candlepin: bootstrap RPM deploys CA certificate file with mode 666", "id": "906207", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=906207"}, "csaw": false, "cvss": {"cvss_base_score": "4.6", "cvss_scoring_vector": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "status": "verified"}, "details": ["modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file."], "name": "CVE-2012-6116", "public_date": "2013-02-21T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2012-6116\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-6116"], "threat_severity": "Moderate"}