CVE-2012-3866

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.8:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.9:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.11:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.12:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.13:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.14:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.16:*:*:*:*:*:*:*
cpe:2.3:a:puppetlabs:puppet:*:*:*:*:*:*:*:*
cpe:2.3:a:puppetlabs:puppet:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:puppetlabs:puppet:2.7.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:41

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-updates/2012-07/msg00036.html - () http://lists.opensuse.org/opensuse-updates/2012-07/msg00036.html -
References () http://puppetlabs.com/security/cve/cve-2012-3866/ - Vendor Advisory () http://puppetlabs.com/security/cve/cve-2012-3866/ - Vendor Advisory
References () http://secunia.com/advisories/50014 - () http://secunia.com/advisories/50014 -
References () http://www.debian.org/security/2012/dsa-2511 - () http://www.debian.org/security/2012/dsa-2511 -
References () http://www.ubuntu.com/usn/USN-1506-1 - () http://www.ubuntu.com/usn/USN-1506-1 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=839135 - () https://bugzilla.redhat.com/show_bug.cgi?id=839135 -
References () https://github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3f - Exploit, Patch () https://github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3f - Exploit, Patch

Information

Published : 2012-08-06 16:55

Updated : 2024-11-21 01:41


NVD link : CVE-2012-3866

Mitre link : CVE-2012-3866

CVE.ORG link : CVE-2012-3866


JSON object : View

Products Affected

puppet

  • puppet_enterprise
  • puppet

puppetlabs

  • puppet
CWE
CWE-264

Permissions, Privileges, and Access Controls