Lucene search

K
githubGitHub Advisory DatabaseGHSA-VRH7-99JH-3FMM
HistoryMay 02, 2022 - 6:10 a.m.

Puppet arbitrary files overwrite via a symlink attack

2022-05-0206:10:33
CWE-59
GitHub Advisory Database
github.com
5
puppet
software
vulnerability
file overwrite
symlink attack

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%

Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.

Affected configurations

Vulners
Node
puppetpuppetRange0.25.00.25.2
OR
puppetpuppetRange0.24.00.24.9
VendorProductVersionCPE
puppetpuppet*cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*

References

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%