CVE-2012-3864
published 2012-08-06CVE-2012-3864: Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet…
PriorityP424medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.91%
77.6th percentile
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.18-1 (bullseye) | puppet 2.7.18-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-07-12·CVSS 4.0
CVE-2012-3864 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in Puppet.
It was discovered that Puppet incorrectly handled certain HTTP GET
requests. An attacker could use this flaw with a valid client certificate
to retrieve arbitrary files from the Puppet primary server.
(CVE-2012-3864)
It was discovered that Puppet incorrectly handled Delete requests. If a
Puppet primary server were reconfigured to allow the "Delete" method, an
attacker on an authenticated host could use this flaw to delete arbitrary
files from the Puppet server, leading to a denial of service.
(CVE-2012-3865)
It was discovered that Puppet incorrectly set file permissions on the
last_run_report.yaml file. An attacker could use this flaw to access
sensitive information. This issue only affected Ubuntu 11.
Red Hat
puppet: authenticated clients allowed to read arbitrary files from the puppet master
vendor_redhat·2012-07-10·CVSS 4.0
CVE-2012-3864 [MEDIUM] puppet: authenticated clients allowed to read arbitrary files from the puppet master
puppet: authenticated clients allowed to read arbitrary files from the puppet master
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-3864: puppet - Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2...
vendor_debian·2012·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864: puppet - Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2...
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
Scope: local
bullseye: resolved (fixed in 2.7.18-1)
GHSA
GHSA-8xhg-x93x-j983: Puppet before 2
ghsa_unreviewed·2022-05-14
CVE-2012-3864 [MEDIUM] CWE-200 GHSA-8xhg-x93x-j983: Puppet before 2
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
OSV
CVE-2012-3864: Puppet before 2
osv·2012-08-06·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864: Puppet before 2
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2012-3864 puppet: authenticated clients allowed to read arbitrary files from the puppet master
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 puppet: authenticated clients allowed to read arbitrary files from the puppet master
CVE-2012-3864 puppet: authenticated clients allowed to read arbitrary files from the puppet master
From puppet labs: CVE-2012-3864 (Arbitrary File Read)
A bug in Puppet 2.6.16 and 2.7.17 allows authenticated clients to read
arbitrary files from the puppet master.
Given a valid certificate and private key, it is possible to construct an
HTTP GET request that will return the contents of an arbitrary file on the
Puppet master. These requests can retrieve any file that the puppet master
has read-access to.
Resolved in Puppet 2.6.17, 2.7.18
Discussion:
Created puppet tracking bugs for this issue
Affects: fedora-17 [bug 839168]
---
Created puppet tracking bugs for this issue
Affects: fedora-16 [bug 839171]
---
External Reference:
http://puppetlabs.com/security/cve/cve-2012-3864/
--
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3864/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839130https://github.com/puppetlabs/puppet/commit/10f6cb8969b4d5a933b333ecb01ce3696b1d57d4https://github.com/puppetlabs/puppet/commit/c3c7462e4066bf3a563987a402bf3ddf278bcd87http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3864/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839130https://github.com/puppetlabs/puppet/commit/10f6cb8969b4d5a933b333ecb01ce3696b1d57d4https://github.com/puppetlabs/puppet/commit/c3c7462e4066bf3a563987a402bf3ddf278bcd87
2012-08-06
Published