1.9
CVSSv2

CVE-2015-7328

Published: 08/01/2016 Updated: 10/07/2019
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Puppet Server in Puppet Enterprise prior to 3.8.x prior to 3.8.3 and 2015.2.x prior to 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to obtain sensitive information via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2015.2.0

puppet puppet enterprise 2015.2.2

puppet puppet enterprise 2015.2.1

puppet puppet enterprise 3.8.2

puppet puppet enterprise 3.8.0

puppet puppet enterprise 3.8.1