lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade puppet | Jul 30, 2024 | Aug 6, 2012 |
| Freebsd | — | Upgrade puppet | Dec 10, 2025 | Jul 10, 2012 |
| Suse | — | Upgrade puppetUpgrade puppet-server | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade puppet-common | Nov 8, 2024 | Aug 6, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub