6
CVSSv2

CVE-2012-1988

Published: 29/05/2012 Updated: 02/02/2024
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Puppet 2.6.x prior to 2.6.15 and 2.7.x prior to 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x prior to 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet

puppet puppet enterprise 1.0

puppet puppet enterprise 1.1

puppet puppet enterprise

fedoraproject fedora 17

fedoraproject fedora 16

fedoraproject fedora 15

debian debian linux 7.0

debian debian linux 6.0

canonical ubuntu linux 11.04

canonical ubuntu linux 11.10

canonical ubuntu linux 10.04

Vendor Advisories

Several security issues were fixed in puppet ...
Several vulnerabilities have been discovered in Puppet, a centralized configuration management system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2012-1906 Puppet is using predictable temporary file names when downloading Mac OS X package files This allows a local attacker to either overwri ...