CVE-2012-3864
Public on 2012-08-06
Modified on 2014-09-14
Description
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 1 | puppet | 2012-10-15 | ALAS-2012-135 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv2 | 2.1 | AV:N/AC:H/Au:S/C:P/I:N/A:N |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:P/I:N/A:N |