CVE-2012-3865
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:N/A:P
Exploitability: 6.8 / Impact: 2.9
Source: NVD
Description
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.
Affected (34)
Products: Puppet: Puppet, Puppet Enterprise · Puppetlabs: Puppet
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.7.10 | |
| Up to 2.7.17 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.6.0 | |
| Up to 2.6.16 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5.1 |
References (18)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
ExploitPatch
Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Timeline
No history available yet.