Lucene search

K
rubygemsRubySecRUBY:PUPPET-2010-0156
HistoryMay 01, 2022 - 9:00 p.m.

Puppet arbitrary files overwrite via a symlink attack

2022-05-0121:00:00
RubySec
puppet.com
9
puppet
symlink attack
arbitrary files overwrite
temporary files

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

7.1

Confidence

High

Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local
users to overwrite arbitrary files via a symlink attack on the
(1) /tmp/daemonout,
(2) /tmp/puppetdoc.txt,
(3) /tmp/puppetdoc.tex, or
(4) /tmp/puppetdoc.aux temporary file.

Affected configurations

Vulners
Node
rubypuppetRange0.24.00.24.9
OR
rubypuppetRange0.25.2
VendorProductVersionCPE
rubypuppet*cpe:2.3:a:ruby:puppet:*:*:*:*:*:*:*:*

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

7.1

Confidence

High