CVE-2012-1988
published 2012-05-29CVE-2012-1988: Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated…
PriorityP434medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
2.63%
83.8th percentile
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | puppet | < puppet 2.7.13-1 (bullseye) | puppet 2.7.13-1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| puppet | puppet | >= 0 < 2.7.13-1 | 2.7.13-1 |
| puppet | puppet | >= 2.6.0 < 2.6.15 | 2.6.15 |
| puppet | puppet | >= 2.6.0 < 2.6.15 | 2.6.15 |
| puppet | puppet | >= 2.7.0 < 2.7.13 | 2.7.13 |
| puppet | puppet | >= 2.7.0 < 2.7.13 | 2.7.13 |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | >= 1.2.0 < 2.5.1 | 2.5.1 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Puppet Arbitrary Command Execution
ghsa·2022-05-14
CVE-2012-1988 [MEDIUM] CWE-77 Puppet Arbitrary Command Execution
Puppet Arbitrary Command Execution
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
OSV
Puppet Arbitrary Command Execution
osv·2022-05-14
CVE-2012-1988 [MEDIUM] Puppet Arbitrary Command Execution
Puppet Arbitrary Command Execution
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
OSV
CVE-2012-1988: Puppet 2
osv·2012-05-29·CVSS 6.0
CVE-2012-1988 [MEDIUM] CVE-2012-1988: Puppet 2
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-04-11·CVSS 3.3
CVE-2012-1906 [LOW] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in puppet.
It was discovered that Puppet used a predictable filename when downloading Mac
OS X package files. A local attacker could exploit this to overwrite arbitrary
files. (CVE-2012-1906)
It was discovered that Puppet incorrectly handled filebucket retrieval
requests. A local attacker could exploit this to read arbitrary files.
(CVE-2012-1986)
It was discovered that Puppet incorrectly handled filebucket store requests. A
local attacker could exploit this to perform a denial of service via resource
exhaustion. (CVE-2012-1987)
It was discovered that Puppet incorrectly handled filebucket requests. A local
attacker could exploit this to execute arbitrary code via a crafted file path.
(CVE-2012-1988)
It was disc
Red Hat
puppet: Filebucket arbitrary code execution
vendor_redhat·2012-04-10·CVSS 6.0
CVE-2012-1988 [MEDIUM] puppet: Filebucket arbitrary code execution
puppet: Filebucket arbitrary code execution
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-1988: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U...
vendor_debian·2012·CVSS 6.0
CVE-2012-1988 [MEDIUM] CVE-2012-1988: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U...
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
Scope: local
bullseye: resolved (fixed in 2.7.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
bugzilla·2012-04-16·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
bugzilla·2012-04-16·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-1988 puppet: Filebucket arbitrary code execution
bugzilla·2012-04-05·CVSS 6.0
CVE-2012-1988 [MEDIUM] CVE-2012-1988 puppet: Filebucket arbitrary code execution
CVE-2012-1988 puppet: Filebucket arbitrary code execution
From Matthaus Litteken :
CVE-2012-1988 (High) [#13518] - Filebucket arbitrary code execution
This requires access to the cert on the agent and an unprivileged
account on the master. By creating a path on the master in a
world-writable location that matches a command string, one can
then make a file bucket request to execute that command.
Discussion:
This is public now.
External Reference:
http://puppetlabs.com/security/cve/cve-2012-1988/
---
Created puppet tracking bugs for this issue
Affects: fedora-all [bug 812955]
Affects: epel-all [bug 812956]
---
Acknowledgements:
Red Hat would like to thank Puppet Labs for reporting this issue.
---
puppet-2.6.16-1.fc16 has been pushed to the Fedora 16 stable repository. If proble
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.htmlhttp://projects.puppetlabs.com/issues/13518http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15http://puppetlabs.com/security/cve/cve-2012-1988/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.osvdb.org/81309http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74796https://hermes.opensuse.org/messages/14523305https://hermes.opensuse.org/messages/15087408http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.htmlhttp://projects.puppetlabs.com/issues/13518http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15http://puppetlabs.com/security/cve/cve-2012-1988/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.osvdb.org/81309http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74796https://hermes.opensuse.org/messages/14523305https://hermes.opensuse.org/messages/15087408
2012-05-29
Published