Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-1426


Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.


Published

2015-02-23T17:59:01.680

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.1 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application puppet facter 1.6.0 Yes
Application puppet facter 1.6.1 Yes
Application puppet facter 1.6.1 Yes
Application puppet facter 1.6.1 Yes
Application puppet facter 1.6.1 Yes
Application puppet facter 1.6.2 Yes
Application puppet facter 1.6.3 Yes
Application puppet facter 1.6.4 Yes
Application puppet facter 1.6.5 Yes
Application puppet facter 1.6.6 Yes
Application puppet facter 1.6.6 Yes
Application puppet facter 1.6.7 Yes
Application puppet facter 1.6.8 Yes
Application puppet facter 1.6.9 Yes
Application puppet facter 1.6.10 Yes
Application puppet facter 1.6.11 Yes
Application puppet facter 1.6.12 Yes
Application puppet facter 1.6.12 Yes
Application puppet facter 1.6.13 Yes
Application puppet facter 1.6.14 Yes
Application puppet facter 1.6.15 Yes
Application puppet facter 1.6.16 Yes
Application puppet facter 1.6.17 Yes
Application puppet facter 1.6.18 Yes
Application puppet facter 1.7.0 Yes
Application puppet facter 1.7.0 Yes
Application puppet facter 1.7.1 Yes
Application puppet facter 1.7.2 Yes
Application puppet facter 1.7.3 Yes
Application puppet facter 1.7.4 Yes
Application puppet facter 1.7.5 Yes
Application puppet facter 1.7.5 Yes
Application puppet facter 2.0.0 Yes
Application puppet facter 2.0.0 Yes
Application puppet facter 2.0.0 Yes
Application puppet facter 2.0.0 Yes
Application puppet facter 2.0.1 Yes
Application puppet facter 2.0.1 Yes
Application puppet facter 2.0.1 Yes
Application puppet facter 2.0.1 Yes
Application puppet facter 2.0.2 Yes
Application puppet facter 2.1.0 Yes
Application puppet facter 2.2.0 Yes
Application puppet facter 2.3.0 Yes
Application puppet facter 2.4.0 Yes
Application puppetlabs facter 1.6.1 Yes
Application puppetlabs facter 1.6.2 Yes
Application puppetlabs facter 1.6.3 Yes
Application puppetlabs facter 1.6.4 Yes
Application puppetlabs facter 1.6.5 Yes
Application puppetlabs facter 1.6.6 Yes
Application puppetlabs facter 1.6.7 Yes
Application puppetlabs facter 1.6.8 Yes
Application puppetlabs facter 1.6.9 Yes
Application puppetlabs facter 1.6.10 Yes
Application puppetlabs facter 1.6.11 Yes
Application puppetlabs facter 1.6.12 Yes
Application puppetlabs facter 1.6.13 Yes
Application puppetlabs facter 1.6.14 Yes
Application puppetlabs facter 1.6.15 Yes
Application puppetlabs facter 1.6.17 Yes
Application puppetlabs facter 1.6.18 Yes
Application puppetlabs facter 1.7.0 Yes
Application puppetlabs facter 1.7.1 Yes
Application puppetlabs facter 1.7.2 Yes
Application puppetlabs facter 1.7.3 Yes
Application puppetlabs facter 1.7.4 Yes
Application puppetlabs facter 1.7.5 Yes
Application puppetlabs facter 1.7.6 Yes
Application puppetlabs facter 2.0.1 Yes

References