Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-3866

Опубликовано: 06 авг. 2012
Источник: ubuntu
Приоритет: medium
CVSS2: 2.1

Описание

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

РелизСтатусПримечание
devel

released

2.7.11-1ubuntu3
hardy

ignored

end of life
lucid

not-affected

0.25.4-2ubuntu6.7
natty

not-affected

2.6.4-2ubuntu2.9
oneiric

released

2.7.1-1ubuntu3.7
precise

released

2.7.11-1ubuntu2.1
upstream

released

2.7.18

Показывать по

2.1 Low

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

debian
больше 13 лет назад

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enter ...

github
больше 8 лет назад

Puppet allows local users to obtain sensitive configuration information

2.1 Low

CVSS2