Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pvx-fwwh-w289

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Puppet does not properly restrict access to node resources

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.

Пакеты

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 2.6.0, <= 2.6.3

2.6.4

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
почти 12 лет назад

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.

nvd
почти 12 лет назад

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.

debian
почти 12 лет назад

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node r ...

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-284