CVE Vulnerabilities

CVE-2012-1986

Published: May 29, 2012 | Modified: Jul 11, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

Affected Software

Name Vendor Start Version End Version
Puppet Puppet 2.6.0 (including) 2.6.0 (including)
Puppet Puppet 2.6.1 (including) 2.6.1 (including)
Puppet Puppet 2.6.2 (including) 2.6.2 (including)
Puppet Puppet 2.6.3 (including) 2.6.3 (including)
Puppet Puppet 2.6.4 (including) 2.6.4 (including)
Puppet Puppet 2.6.5 (including) 2.6.5 (including)
Puppet Puppet 2.6.6 (including) 2.6.6 (including)
Puppet Puppet 2.6.7 (including) 2.6.7 (including)
Puppet Puppet 2.6.8 (including) 2.6.8 (including)
Puppet Puppet 2.6.9 (including) 2.6.9 (including)
Puppet Puppet 2.6.10 (including) 2.6.10 (including)
Puppet Puppet 2.6.11 (including) 2.6.11 (including)
Puppet Puppet 2.6.12 (including) 2.6.12 (including)
Puppet Puppet 2.6.13 (including) 2.6.13 (including)
Puppet Puppet 2.6.14 (including) 2.6.14 (including)
CloudForms for RHEL 6 RedHat converge-ui-devel-0:1.0.4-1.el6cf *
CloudForms for RHEL 6 RedHat puppet-0:2.6.17-2.el6cf *
CloudForms for RHEL 6 RedHat rubygem-actionpack-1:3.0.10-10.el6cf *
CloudForms for RHEL 6 RedHat rubygem-activerecord-1:3.0.10-6.el6cf *
CloudForms for RHEL 6 RedHat rubygem-activesupport-1:3.0.10-4.el6cf *
CloudForms for RHEL 6 RedHat rubygem-chunky_png-0:1.2.0-3.el6cf *
CloudForms for RHEL 6 RedHat rubygem-compass-0:0.11.5-2.el6cf *
CloudForms for RHEL 6 RedHat rubygem-compass-960-plugin-0:0.10.4-2.el6cf *
CloudForms for RHEL 6 RedHat rubygem-delayed_job-0:2.1.4-2.el6cf *
CloudForms for RHEL 6 RedHat rubygem-ldap_fluff-0:0.1.3-1.el6_3 *
CloudForms for RHEL 6 RedHat rubygem-mail-0:2.3.0-3.el6cf *
CloudForms for RHEL 6 RedHat rubygem-net-ldap-0:0.1.1-3.el6cf *
Puppet Ubuntu devel *
Puppet Ubuntu hardy *
Puppet Ubuntu lucid *
Puppet Ubuntu maverick *
Puppet Ubuntu natty *
Puppet Ubuntu oneiric *

References