CVE Vulnerabilities

CVE-2017-10689

Improper Privilege Management

Published: Feb 09, 2018 | Modified: Oct 03, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Puppet Puppet * 5.3.4 (excluding)
Puppet Puppet 1.10.0 (including) 1.10.10 (excluding)
Puppet_enterprise Puppet * 2016.4.10 (excluding)
Puppet_enterprise Puppet 2017.1.0 (including) 2017.3.4 (excluding)

Potential Mitigations

References