Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g89m-3wjw-h857

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Puppet vulnerable to Path Traversal

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

Пакеты

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

< 2.6.17

2.6.17

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.18

2.7.18

EPSS

Процентиль: 84%
0.0215
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

redhat
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

nvd
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

debian
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Pu ...

EPSS

Процентиль: 84%
0.0215
Низкий

Дефекты

CWE-22