2.1 CVE-2012-1986
Ransomware Risk
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
https://nvd.nist.gov/vuln/detail/CVE-2012-1986
Categories
CWE-264
References
BID
CONFIRM
http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15 |
http://puppetlabs.com/security/cve/cve-2012-1986/ Vendor Advisory |
DEBIAN
FEDORA
MISC
SECUNIA
SUSE
UBUNTU
XF
CPE
cpe | start | end |
---|---|---|
Configuration 1 | ||
cpe:2.3:a:puppet:puppet:2.6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.11:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.13:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.6.14:*:*:*:*:*:*:* | ||
Configuration 2 | ||
cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet:2.7.11:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:2.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppetlabs:puppet:2.7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppetlabs:puppet:2.7.1:*:*:*:*:*:*:* | ||
Configuration 3 | ||
cpe:2.3:a:puppet:puppet_enterprise:1.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:1.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:1.2.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:1.2.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:1.2.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:2.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppet:puppet_enterprise:2.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppetlabs:puppet_enterprise_users:1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:puppetlabs:puppet_enterprise_users:1.1:*:*:*:*:*:*:* |
REMEDIATION
EXPLOITS
Exploit-db.com
id | description | date | |
---|---|---|---|
No known exploits |
Other (github, ...)
Url |
---|
No known exploits |
CAPEC
Common Attack Pattern Enumerations and Classifications
id | description | severity |
---|---|---|
No entry |
MITRE
Sherlock® flash
Take a picture of your computer network in a few clicks !
The Sherlock® flash audit solution allows you to perform an audit to strengthen the security of your IT assets. Vulnerability analysis of your physical and virtual equipment. Patch planning by priority level and time available. Detailed and intuitive reporting.
