Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade puppet | Jul 30, 2024 | May 29, 2012 |
| Gentoo Linux | — | Upgrade app-admin/puppet. | Oct 30, 2017 | May 29, 2012 |
| Suse | — | Upgrade puppetUpgrade puppet-server | Feb 17, 2015 | May 29, 2012 |
| Ubuntu | — | Upgrade puppet-common | Nov 8, 2024 | May 29, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub