2.1
CVSSv2

CVE-2015-1426

Published: 23/02/2015 Updated: 11/07/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Puppet Labs Facter 1.6.0 up to and including 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet facter 1.6.0

puppetlabs facter 1.6.5

puppet facter 1.6.6

puppetlabs facter 1.6.6

puppet facter 1.6.7

puppet facter 1.6.13

puppetlabs facter 1.6.13

puppet facter 1.6.14

puppetlabs facter 1.6.14

puppetlabs facter 1.7.2

puppet facter 1.7.3

puppetlabs facter 1.7.3

puppet facter 1.7.4

puppetlabs facter 2.0.1

puppet facter 2.0.2

puppet facter 2.1.0

puppetlabs facter 1.6.1

puppet facter 1.6.2

puppetlabs facter 1.6.2

puppet facter 1.6.3

puppetlabs facter 1.6.9

puppet facter 1.6.10

puppetlabs facter 1.6.10

puppet facter 1.6.11

puppetlabs facter 1.6.17

puppet facter 1.6.18

puppetlabs facter 1.6.18

puppet facter 1.7.0

puppetlabs facter 1.7.6

puppet facter 2.0.0

puppet facter 2.2.0

puppet facter 1.6.1

puppet facter 1.6.4

puppet facter 1.6.5

puppet facter 1.6.8

puppet facter 1.6.9

puppetlabs facter 1.6.11

puppet facter 1.6.12

puppetlabs facter 1.6.15

puppet facter 1.6.17

puppet facter 1.7.1

puppet facter 1.7.2

puppetlabs facter 1.7.4

puppet facter 1.7.5

puppet facter 2.0.1

puppet facter 2.4.0

puppetlabs facter 1.6.3

puppetlabs facter 1.6.4

puppetlabs facter 1.6.7

puppetlabs facter 1.6.8

puppetlabs facter 1.6.12

puppet facter 1.6.15

puppet facter 1.6.16

puppetlabs facter 1.7.0

puppetlabs facter 1.7.1

puppetlabs facter 1.7.5

puppet facter 2.3.0

Vendor Advisories

Debian Bug report logs - #778265 facter: CVE-2015-1426 Package: facter; Maintainer for facter is Puppet Package Maintainers <pkg-puppet-devel@listsaliothdebianorg>; Source for facter is src:facter (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 12 Feb 2015 22:30:01 UTC Severity: ...