VDB
Sign up
MEDIUM

GHSA-8c56-v25w-f89c

Puppet arbitrary file overwrite

Quick fix

GHSA-8c56-v25w-f89c — puppet: upgrade to the fixed version with the command below.

bundle update puppet

Details

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/puppet
Introduced in: 2.7.0Fixed in: 2.7.5
Fixbundle update puppet
RubyGems/puppet
Introduced in: 0Fixed in: 2.6.11
Fixbundle update puppet

References