Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vw22-465p-8j5w

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Tarball permission preservation in puppet

When installing a module using the system tar, the PMT will filter filesystem permissions to a sane value. This may just be based on the user's umask.

When using minitar, files are unpacked with whatever permissions are in the tarball. This is potentially unsafe, as tarballs can be easily created with weird permissions.

Пакеты

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

< 4.10.10

4.10.10

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 5.0.0, < 5.3.4

5.3.4

EPSS

Процентиль: 26%
0.00092
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

CVSS3: 2.8
redhat
больше 8 лет назад

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

CVSS3: 5.5
nvd
почти 8 лет назад

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

CVSS3: 5.5
debian
почти 8 лет назад

In previous versions of Puppet Agent it was possible to install a modu ...

suse-cvrf
почти 8 лет назад

Security update for rubygem-puppet

EPSS

Процентиль: 26%
0.00092
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-269