CVE Vulnerabilities

CVE-2015-1029

Published: Jan 16, 2015 | Modified: Jul 11, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

Affected Software

Name Vendor Start Version End Version
Stdlib Puppet 2.1.0 (including) 2.1.0 (including)
Stdlib Puppet 2.1.1 (including) 2.1.1 (including)
Stdlib Puppet 2.1.2 (including) 2.1.2 (including)
Stdlib Puppet 2.1.3 (including) 2.1.3 (including)
Stdlib Puppet 2.2.0 (including) 2.2.0 (including)
Stdlib Puppet 2.2.1 (including) 2.2.1 (including)
Stdlib Puppet 2.3.0 (including) 2.3.0 (including)
Stdlib Puppet 2.3.1 (including) 2.3.1 (including)
Stdlib Puppet 2.3.2 (including) 2.3.2 (including)
Stdlib Puppet 2.3.3 (including) 2.3.3 (including)
Stdlib Puppet 2.4.0 (including) 2.4.0 (including)
Stdlib Puppet 2.5.0 (including) 2.5.0 (including)
Stdlib Puppet 3.0.0 (including) 3.0.0 (including)
Stdlib Puppet 4.1.0 (including) 4.1.0 (including)
Stdlib Puppet 4.2.0 (including) 4.2.0 (including)
Stdlib Puppet 4.2.1 (including) 4.2.1 (including)
Stdlib Puppet 4.2.2 (including) 4.2.2 (including)
Stdlib Puppet 4.3.0 (including) 4.3.0 (including)
Stdlib Puppet 4.3.1 (including) 4.3.1 (including)
Stdlib Puppet 4.3.2 (including) 4.3.2 (including)
Stdlib Puppet 4.4.0 (including) 4.4.0 (including)
Stdlib Puppet 4.5.0 (including) 4.5.0 (including)
Puppet-module-puppetlabs-stdlib Ubuntu artful *
Puppet-module-puppetlabs-stdlib Ubuntu trusty *
Puppet-module-puppetlabs-stdlib Ubuntu upstream *
Puppet-module-puppetlabs-stdlib Ubuntu utopic *
Puppet-module-puppetlabs-stdlib Ubuntu vivid *
Puppet-module-puppetlabs-stdlib Ubuntu wily *
Puppet-module-puppetlabs-stdlib Ubuntu yakkety *
Puppet-module-puppetlabs-stdlib Ubuntu zesty *

References