CVE Vulnerabilities

CVE-2012-1986

Published: May 29, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet2.6.0 (including)2.6.0 (including)
PuppetPuppet2.6.1 (including)2.6.1 (including)
PuppetPuppet2.6.2 (including)2.6.2 (including)
PuppetPuppet2.6.3 (including)2.6.3 (including)
PuppetPuppet2.6.4 (including)2.6.4 (including)
PuppetPuppet2.6.5 (including)2.6.5 (including)
PuppetPuppet2.6.6 (including)2.6.6 (including)
PuppetPuppet2.6.7 (including)2.6.7 (including)
PuppetPuppet2.6.8 (including)2.6.8 (including)
PuppetPuppet2.6.9 (including)2.6.9 (including)
PuppetPuppet2.6.10 (including)2.6.10 (including)
PuppetPuppet2.6.11 (including)2.6.11 (including)
PuppetPuppet2.6.12 (including)2.6.12 (including)
PuppetPuppet2.6.13 (including)2.6.13 (including)
PuppetPuppet2.6.14 (including)2.6.14 (including)
CloudForms for RHEL 6RedHatconverge-ui-devel-0:1.0.4-1.el6cf*
CloudForms for RHEL 6RedHatpuppet-0:2.6.17-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-actionpack-1:3.0.10-10.el6cf*
CloudForms for RHEL 6RedHatrubygem-activerecord-1:3.0.10-6.el6cf*
CloudForms for RHEL 6RedHatrubygem-activesupport-1:3.0.10-4.el6cf*
CloudForms for RHEL 6RedHatrubygem-chunky_png-0:1.2.0-3.el6cf*
CloudForms for RHEL 6RedHatrubygem-compass-0:0.11.5-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-compass-960-plugin-0:0.10.4-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-delayed_job-0:2.1.4-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-ldap_fluff-0:0.1.3-1.el6_3*
CloudForms for RHEL 6RedHatrubygem-mail-0:2.3.0-3.el6cf*
CloudForms for RHEL 6RedHatrubygem-net-ldap-0:0.1.1-3.el6cf*
PuppetUbuntudevel*
PuppetUbuntuhardy*
PuppetUbuntulucid*
PuppetUbuntumaverick*
PuppetUbuntunatty*
PuppetUbuntuoneiric*

References