Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
2012-05-29T20:55:08.243
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.0 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | puppet | puppet | < 2.6.15 | Yes |
Application | puppet | puppet | < 2.7.13 | Yes |
Application | puppet | puppet_enterprise | < 2.5.1 | Yes |
Application | puppet | puppet_enterprise | 1.0 | Yes |
Application | puppet | puppet_enterprise | 1.1 | Yes |
Operating System | fedoraproject | fedora | 15 | Yes |
Operating System | fedoraproject | fedora | 16 | Yes |
Operating System | fedoraproject | fedora | 17 | Yes |
Operating System | debian | debian_linux | 6.0 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | canonical | ubuntu_linux | 10.04 | Yes |
Operating System | canonical | ubuntu_linux | 11.04 | Yes |
Operating System | canonical | ubuntu_linux | 11.10 | Yes |