CVE Vulnerabilities

CVE-2015-1029

Published: Jan 16, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

Affected Software

NameVendorStart VersionEnd Version
StdlibPuppet2.1.0 (including)2.1.0 (including)
StdlibPuppet2.1.1 (including)2.1.1 (including)
StdlibPuppet2.1.2 (including)2.1.2 (including)
StdlibPuppet2.1.3 (including)2.1.3 (including)
StdlibPuppet2.2.0 (including)2.2.0 (including)
StdlibPuppet2.2.1 (including)2.2.1 (including)
StdlibPuppet2.3.0 (including)2.3.0 (including)
StdlibPuppet2.3.1 (including)2.3.1 (including)
StdlibPuppet2.3.2 (including)2.3.2 (including)
StdlibPuppet2.3.3 (including)2.3.3 (including)
StdlibPuppet2.4.0 (including)2.4.0 (including)
StdlibPuppet2.5.0 (including)2.5.0 (including)
StdlibPuppet3.0.0 (including)3.0.0 (including)
StdlibPuppet4.1.0 (including)4.1.0 (including)
StdlibPuppet4.2.0 (including)4.2.0 (including)
StdlibPuppet4.2.1 (including)4.2.1 (including)
StdlibPuppet4.2.2 (including)4.2.2 (including)
StdlibPuppet4.3.0 (including)4.3.0 (including)
StdlibPuppet4.3.1 (including)4.3.1 (including)
StdlibPuppet4.3.2 (including)4.3.2 (including)
StdlibPuppet4.4.0 (including)4.4.0 (including)
StdlibPuppet4.5.0 (including)4.5.0 (including)
Puppet-module-puppetlabs-stdlibUbuntuartful*
Puppet-module-puppetlabs-stdlibUbuntutrusty*
Puppet-module-puppetlabs-stdlibUbuntuupstream*
Puppet-module-puppetlabs-stdlibUbuntuutopic*
Puppet-module-puppetlabs-stdlibUbuntuvivid*
Puppet-module-puppetlabs-stdlibUbuntuwily*
Puppet-module-puppetlabs-stdlibUbuntuyakkety*
Puppet-module-puppetlabs-stdlibUbuntuzesty*

References