MEDIUM
GHSA-9pvx-fwwh-w289
Puppet does not properly restrict access to node resources
Quick fix
GHSA-9pvx-fwwh-w289 — puppet: upgrade to the fixed version with the command below.
bundle update puppetDetails
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2011-0528[ADVISORY]
- https://github.com/puppetlabs/puppet/commit/eee1a9cdaa5cab6222c8e6ab087d319f976fa4e3[WEB]
- https://github.com/puppetlabs/puppet[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2011-0528.yml[WEB]
- http://www.mail-archive.com/puppet-users@googlegroups.com/msg16429.html[WEB]
- http://www.openwall.com/lists/oss-security/2011/01/27/6[WEB]
- http://www.openwall.com/lists/oss-security/2011/01/31/5[WEB]
- http://www.ubuntu.com/usn/USN-1365-1[WEB]