Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jxj-9r5f-w3m2

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Puppet allows local users to obtain sensitive configuration information

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

Пакеты

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.18

2.7.18

EPSS

Процентиль: 16%
0.0005
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

nvd
больше 13 лет назад

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

debian
больше 13 лет назад

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enter ...

EPSS

Процентиль: 16%
0.0005
Низкий