Show plain JSON{"acknowledgement": "This issue was discovered by James Labocki (Red Hat).", "affected_release": [{"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "candlepin-0:0.7.8.1-1.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "gofer-0:0.66.1-2.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "grinder-0:0.0.150-1.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-0:1.1.12-22.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-agent-0:1.1.2-1.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-certs-tools-0:1.1.8-1.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-cli-0:1.1.8-12.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-cli-tests-0:1.1.5-2.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-configure-0:1.1.9-12.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "katello-selinux-0:1.1.1-2.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "pulp-0:1.1.14-1.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "quartz-0:2.1.5-4.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el6", "package": "rubygem-apipie-rails-0:0.0.11-3.el6cf", "product_name": "CloudForms for RHEL 6", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el5", "package": "gofer-0:0.66.1-2.el5", "product_name": "CloudForms Tools for RHEL 5", "release_date": "2012-12-04T00:00:00Z"}, {"advisory": "RHSA-2012:1543", "cpe": "cpe:/a:cloudforms_tools:1::el5", "package": "katello-agent-0:1.1.2-1.el5", "product_name": "CloudForms Tools for RHEL 5", "release_date": "2012-12-04T00:00:00Z"}], "bugzilla": {"description": "grinder: /var/lib/pulp/cache/grinder directory is world-writeable", "id": "882138", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=882138"}, "csaw": false, "cvss": {"cvss_base_score": "4.6", "cvss_scoring_vector": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "status": "verified"}, "details": ["Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files."], "name": "CVE-2012-5605", "package_state": [{"cpe": "cpe:/a:redhat:rhui:2", "fix_state": "Will not fix", "package_name": "grinder", "product_name": "RHUI for RHEL 6"}], "public_date": "2012-12-04T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2012-5605\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-5605"], "statement": "Red Hat Update Infrastructure 2.1.3 is now in Production 2 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Update Infrastructure Life Cycle: https://access.redhat.com/support/policy/updates/rhui.", "threat_severity": "Moderate"}