VDB
Sign up
MEDIUM

GHSA-92v7-pq4h-58j5

facter, hiera, mcollective-client, and puppet affected by untrusted search path vulnerability

Quick fix

GHSA-92v7-pq4h-58j5 — facter: upgrade to the fixed version with the command below.

bundle update facter

Details

Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) `rubygems/defaults/operating_system.rb`, (2) `Win32API.rb`, (3) `Win32API.so`, (4) `safe_yaml.rb`, (5) `safe_yaml/deep.rb`, or (6) `safe_yaml/deep.so`; or (7) `operatingsystem.rb`, (8) `operatingsystem.so`, (9) `osfamily.rb`, or (10) `osfamily.so` in `puppet/confine`.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/facter
Introduced in: 0Fixed in: 1.7.6
Fixbundle update facter
RubyGems/facter
Introduced in: 2.0.0Fixed in: 2.0.2
Fixbundle update facter
RubyGems/hiera
Introduced in: 0Fixed in: 1.3.4
Fixbundle update hiera
RubyGems/puppet
Introduced in: 0Fixed in: 2.7.26
Fixbundle update puppet
RubyGems/puppet
Introduced in: 3.0.0Fixed in: 3.6.2
Fixbundle update puppet
RubyGems/mcollective-client
Introduced in: 0Fixed in: 2.5.2
Fixbundle update mcollective-client

References