Puppet

Puppet

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 27.06.2012 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).

  • EPSS 0.49%
  • Veröffentlicht 29.05.2012 20:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute ar...

  • EPSS 0.74%
  • Veröffentlicht 29.05.2012 20:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (m...

  • EPSS 0.37%
  • Veröffentlicht 29.05.2012 20:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbi...

  • EPSS 0.06%
  • Veröffentlicht 29.05.2012 20:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwr...

  • EPSS 0.07%
  • Veröffentlicht 29.05.2012 20:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k...

  • EPSS 0.04%
  • Veröffentlicht 29.05.2012 20:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which al...

  • EPSS 2.78%
  • Veröffentlicht 27.10.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the cer...

  • EPSS 0.04%
  • Veröffentlicht 27.10.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.

  • EPSS 0.03%
  • Veröffentlicht 27.10.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.