Lucene search

K
osvGoogleOSV:GHSA-VRH7-99JH-3FMM
HistoryMay 02, 2022 - 6:10 a.m.

Puppet arbitrary files overwrite via a symlink attack

2022-05-0206:10:33
Google
osv.dev
7
puppet
arbitrary files overwrite
symlink attack
temporary file

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%

Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.

References

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.1%