Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-7328


Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to obtain sensitive information via unspecified vectors.


Published

2016-01-08T19:59:03.723

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 4.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application puppet puppet_enterprise 3.8.0 Yes
Application puppet puppet_enterprise 3.8.1 Yes
Application puppet puppet_enterprise 3.8.2 Yes
Application puppet puppet_enterprise 2015.2.0 Yes
Application puppet puppet_enterprise 2015.2.1 Yes
Application puppet puppet_enterprise 2015.2.2 Yes

References