CVE-2011-3848
published 2011-10-27CVE-2011-3848: Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR)…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.11%
62.5th percentile
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.3-2 (bullseye) | puppet 2.7.3-2 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.3-2 | 2.7.3-2 |
| puppetlabs | puppet | — | — |
| puppetlabs | puppet | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerability
vendor_ubuntu·2011-09-29
CVE-2011-3848 Puppet vulnerability
Title: Puppet vulnerability
Summary: An attacker could send crafted input to puppet and cause it to overwrite
files.
Kristian Erik Hermansen discovered a directory traversal vulnerability in
the SSLFile indirection base class. A remote attacker could exploit this to
overwrite files with the privileges of the Puppet Master.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
puppet: Directory traversal attack by processing certain x509 certificate signing requests
vendor_redhat·2011-09-29·CVSS 5.0
CVE-2011-3848 [MEDIUM] puppet: Directory traversal attack by processing certain x509 certificate signing requests
puppet: Directory traversal attack by processing certain x509 certificate signing requests
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2011-3848: puppet - Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before...
vendor_debian·2011·CVSS 5.0
CVE-2011-3848 [MEDIUM] CVE-2011-3848: puppet - Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before...
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
Scope: local
bullseye: resolved (fixed in 2.7.3-2)
GHSA
GHSA-fg2j-w8mh-wrmp: Directory traversal vulnerability in Puppet 2
ghsa_unreviewed·2022-05-14
CVE-2011-3848 [MEDIUM] CWE-22 GHSA-fg2j-w8mh-wrmp: Directory traversal vulnerability in Puppet 2
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
OSV
CVE-2011-3848: Directory traversal vulnerability in Puppet 2
osv·2011-10-27·CVSS 5.0
CVE-2011-3848 [MEDIUM] CVE-2011-3848: Directory traversal vulnerability in Puppet 2
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
bugzilla·2011-09-30·CVSS 5.0
CVE-2011-3870 [MEDIUM] CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644
Please note: this issue a
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
bugzilla·2011-09-30·CVSS 5.0
CVE-2011-3870 [MEDIUM] CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644
Please note: this issue aff
Bugzilla
CVE-2011-3848 puppet: Directory traversal attack by processing certain x509 certificate signing requests
bugzilla·2011-09-29·CVSS 5.0
CVE-2011-3848 [MEDIUM] CVE-2011-3848 puppet: Directory traversal attack by processing certain x509 certificate signing requests
CVE-2011-3848 puppet: Directory traversal attack by processing certain x509 certificate signing requests
A directory traversal flaw was found in the way SSLFile and YAML Puppet indirector base classes performed management or certain, user-supplied x509 certificate signing requests. An authenticated attacker could use this flaw to overwrite arbitrary system file, accessible with the privileges of the Puppet Master application.
References:
[1] http://groups.google.com/group/puppet-users/browse_thread/thread/e57ce2740feb9406
[2] https://bugs.gentoo.org/show_bug.cgi?id=384859
Discussion:
Created attachment 525509
Puppet upstream patch against v2.7.x branch
---
Created attachment 525510
Puppet upstream patch against v2.6.x branch
---
Created attachment 525511
Puppet upstream patch again
http://lists.opensuse.org/opensuse-updates/2011-10/msg00033.htmlhttp://secunia.com/advisories/46628http://www.debian.org/security/2011/dsa-2314http://www.ubuntu.com/usn/USN-1217-1https://groups.google.com/group/puppet-announce/browse_thread/thread/e57ce2740feb9406https://puppet.com/security/cve/cve-2011-3848http://lists.opensuse.org/opensuse-updates/2011-10/msg00033.htmlhttp://secunia.com/advisories/46628http://www.debian.org/security/2011/dsa-2314http://www.ubuntu.com/usn/USN-1217-1https://groups.google.com/group/puppet-announce/browse_thread/thread/e57ce2740feb9406https://puppet.com/security/cve/cve-2011-3848
2011-10-27
Published