CVE Vulnerabilities

CVE-2015-1029

Published: Jan 16, 2015 | Modified: Jul 11, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

Affected Software

Name Vendor Start Version End Version
Stdlib Puppet 2.1.0 (including) 2.1.0 (including)
Stdlib Puppet 2.1.1 (including) 2.1.1 (including)
Stdlib Puppet 2.1.2 (including) 2.1.2 (including)
Stdlib Puppet 2.1.3 (including) 2.1.3 (including)
Stdlib Puppet 2.2.0 (including) 2.2.0 (including)
Stdlib Puppet 2.2.1 (including) 2.2.1 (including)
Stdlib Puppet 2.3.0 (including) 2.3.0 (including)
Stdlib Puppet 2.3.1 (including) 2.3.1 (including)
Stdlib Puppet 2.3.2 (including) 2.3.2 (including)
Stdlib Puppet 2.3.3 (including) 2.3.3 (including)
Stdlib Puppet 2.4.0 (including) 2.4.0 (including)
Stdlib Puppet 2.5.0 (including) 2.5.0 (including)
Stdlib Puppet 3.0.0 (including) 3.0.0 (including)
Stdlib Puppet 4.1.0 (including) 4.1.0 (including)
Stdlib Puppet 4.2.0 (including) 4.2.0 (including)
Stdlib Puppet 4.2.1 (including) 4.2.1 (including)
Stdlib Puppet 4.2.2 (including) 4.2.2 (including)
Stdlib Puppet 4.3.0 (including) 4.3.0 (including)
Stdlib Puppet 4.3.1 (including) 4.3.1 (including)
Stdlib Puppet 4.3.2 (including) 4.3.2 (including)
Stdlib Puppet 4.4.0 (including) 4.4.0 (including)
Stdlib Puppet 4.5.0 (including) 4.5.0 (including)

References