2.1
CVSSv2

CVE-2012-3866

Published: 06/08/2012 Updated: 10/07/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

lib/puppet/defaults.rb in Puppet 2.7.x prior to 2.7.18, and Puppet Enterprise prior to 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet 2.7.12

puppet puppet 2.7.11

puppet puppet 2.7.3

puppetlabs puppet 2.7.1

puppet puppet 2.7.14

puppet puppet 2.7.13

puppet puppet 2.7.5

puppet puppet 2.7.4

puppetlabs puppet

puppet puppet 2.7.16

puppet puppet 2.7.8

puppet puppet 2.7.6

puppet puppet 2.7.10

puppet puppet 2.7.9

puppet puppet 2.7.2

puppetlabs puppet 2.7.0

puppet puppet enterprise

Vendor Advisories

Several security issues were fixed in Puppet ...
Several security vulnerabilities have been found in Puppet, a centralized configuration management: CVE-2012-3864 Authenticated clients could read arbitrary files on the puppet master CVE-2012-3865 Authenticated clients could delete arbitrary files on the puppet master CVE-2012-3866 The report of the most recent Puppet run was sto ...
Directory traversal vulnerability in lib/puppet/reports/storerb in Puppet before 2617 and 27x before 2718, and Puppet Enterprise before 252, when Delete is enabled in authconf, allows remote authenticated users to delete arbitrary files on the puppet master server via a (dot dot) in a node name Puppet before 2617 and 27x before 2 ...