CVE-2011-0528
published 2014-02-17CVE-2011-0528: Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources…
PriorityP429medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
1.65%
74.0th percentile
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.6.2-3 (bullseye) | puppet 2.6.2-3 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.6.2-3 | 2.6.2-3 |
| puppet | puppet | >= 2.6.0 < 2.6.4 | 2.6.4 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Puppet does not properly restrict access to node resources
osv·2022-05-14
CVE-2011-0528 [MEDIUM] Puppet does not properly restrict access to node resources
Puppet does not properly restrict access to node resources
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
GHSA
Puppet does not properly restrict access to node resources
ghsa·2022-05-14
CVE-2011-0528 [MEDIUM] CWE-284 Puppet does not properly restrict access to node resources
Puppet does not properly restrict access to node resources
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
OSV
CVE-2011-0528: Puppet 2
osv·2014-02-17·CVSS 5.5
CVE-2011-0528 [MEDIUM] CVE-2011-0528: Puppet 2
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Ubuntu
Puppet vulnerability
vendor_ubuntu·2012-02-14
CVE-2011-0528 Puppet vulnerability
Title: Puppet vulnerability
Summary: Puppet would allow unintended access to resources over the network.
It was discovered that Puppet would allow remote ralsh under certain
circumstances. An attacker on an authenticated puppet node could exploit
this to view or manipulate resources on other Puppet nodes.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-0528: puppet - Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, ...
vendor_debian·2011·CVSS 5.5
CVE-2011-0528 [MEDIUM] CVE-2011-0528: puppet - Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, ...
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 2.6.2-3)
Red Hat
CVE-2011-0528: Puppet 2
vendor_redhat·CVSS 5.5
CVE-2011-0528 [MEDIUM] CVE-2011-0528: Puppet 2
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Statement: Not vulnerable. This issue did not affect the versions of Puppet in any Red Hat product.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.mail-archive.com/puppet-users%40googlegroups.com/msg16429.htmlhttp://www.openwall.com/lists/oss-security/2011/01/27/6http://www.openwall.com/lists/oss-security/2011/01/31/5http://www.ubuntu.com/usn/USN-1365-1http://www.mail-archive.com/puppet-users%40googlegroups.com/msg16429.htmlhttp://www.openwall.com/lists/oss-security/2011/01/27/6http://www.openwall.com/lists/oss-security/2011/01/31/5http://www.ubuntu.com/usn/USN-1365-1
2014-02-17
Published