Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1426

Опубликовано: 10 фев. 2015
Источник: redhat
CVSS2: 1.7
EPSS Низкий

Описание

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

Отчет

This issue did not affect the versions of facter as shipped with various Red Hat products as they do not use puppet and facter to control Amazon EC2 instances directly.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack ForemanfacterNot affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)facterNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)facterNot affected
Red Hat Enterprise MRG 1facterNot affected
Red Hat OpenShift Enterprise 2facterNot affected
Red Hat OpenStack Platform 4facterNot affected
Red Hat Satellite 6facterNot affected
Red Hat Subscription Asset ManagerfacterNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1191538facter: potential sensitive information leakage in Facter's Amazon EC2 metadata facts handling

EPSS

Процентиль: 18%
0.00059
Низкий

1.7 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

nvd
почти 11 лет назад

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

debian
почти 11 лет назад

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains s ...

github
больше 3 лет назад

Puppet Labs Facter allows local users to obtain sensitive Amazon EC2 IAM instance metadata

EPSS

Процентиль: 18%
0.00059
Низкий

1.7 Low

CVSS2