Puppet allows local users to obtain sensitive configuration information
Low severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
Aug 6, 2012
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Nov 10, 2023
lib/puppet/defaults.rb
in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions forlast_run_report.yaml
, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.References