VDB
Sign up
MEDIUM

GHSA-mpmx-gm5v-q789

Puppet uses predictable filenames, allowing arbitrary file overwrite

Quick fix

GHSA-mpmx-gm5v-q789 — puppet: upgrade to the fixed version with the command below.

bundle update puppet

Details

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in `--edit` mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/puppet
Introduced in: 2.7.0Fixed in: 2.7.5
Fixbundle update puppet
RubyGems/puppet
Introduced in: 0Fixed in: 2.6.11
Fixbundle update puppet

References