Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the masters cache via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Puppet | Puppetlabs | * | 2.6.17 (including) |
OpenStack Folsom for RHEL 6 | RedHat | puppet-0:2.6.18-1.el6ost | * |
Puppet | Ubuntu | devel | * |
Puppet | Ubuntu | hardy | * |
Puppet | Ubuntu | lucid | * |
Puppet | Ubuntu | oneiric | * |
Puppet | Ubuntu | precise | * |
Puppet | Ubuntu | quantal | * |
Puppet | Ubuntu | upstream | * |