Описание
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 2.7.11-1ubuntu3 |
| hardy | ignored | end of life |
| lucid | released | 0.25.4-2ubuntu6.8 |
| natty | released | 2.6.4-2ubuntu2.10 |
| oneiric | released | 2.7.1-1ubuntu3.7 |
| precise | released | 2.7.11-1ubuntu2.1 |
| upstream | released | 2.6.17,2.7.18 |
Показывать по
EPSS
4 Medium
CVSS2
Связанные уязвимости
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise be ...
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
EPSS
4 Medium
CVSS2