Описание
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat CloudForms Tools 1 | puppet | Affected | ||
Red Hat Enterprise MRG 1 | puppet | Will not fix | ||
CloudForms for RHEL 6 | converge-ui-devel | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | puppet | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | rubygem-actionpack | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | rubygem-activerecord | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | rubygem-activesupport | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | rubygem-chunky_png | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | rubygem-compass | Fixed | RHSA-2012:1542 | 04.12.2012 |
CloudForms for RHEL 6 | rubygem-compass-960-plugin | Fixed | RHSA-2012:1542 | 04.12.2012 |
Показывать по
Дополнительная информация
Статус:
3.6 Low
CVSS2
Связанные уязвимости
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterpr ...
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
3.6 Low
CVSS2