SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1986

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read…

LOW 2.1EPSS 1.47%

Does this matter?

Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.

Description

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

CVSS 2.0
2.1 LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
EPSS
1.47% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
puppet/puppet · puppet/puppet enterprise · puppetlabs/puppet · puppetlabs/puppet enterprise users
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.