Lucene search

K
osvGoogleOSV:GHSA-6XXQ-J39W-G3F6
HistoryMay 14, 2022 - 12:56 a.m.

Puppet Arbitrary Command Execution

2022-05-1400:56:45
Google
osv.dev
10
puppet
arbitrary command execution
remote authenticated users
file creation permissions.

AI Score

7.3

Confidence

Low

EPSS

0.005

Percentile

75.6%

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.

References

AI Score

7.3

Confidence

Low

EPSS

0.005

Percentile

75.6%