Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-3865

Опубликовано: 06 авг. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5

Описание

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

РелизСтатусПримечание
devel

released

2.7.11-1ubuntu3
hardy

ignored

end of life
lucid

released

0.25.4-2ubuntu6.8
natty

released

2.6.4-2ubuntu2.10
oneiric

released

2.7.1-1ubuntu3.7
precise

released

2.7.11-1ubuntu2.1
upstream

released

2.6.17,2.7.18

Показывать по

EPSS

Процентиль: 84%
0.0215
Низкий

3.5 Low

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

nvd
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

debian
больше 13 лет назад

Directory traversal vulnerability in lib/puppet/reports/store.rb in Pu ...

github
больше 8 лет назад

Puppet vulnerable to Path Traversal

EPSS

Процентиль: 84%
0.0215
Низкий

3.5 Low

CVSS2