cbcvebase.
CVE-2012-3865
published 2012-08-06

CVE-2012-3865: Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when…

low3.5CVSS 3.1
AVNACMAuSCNINAP
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debianpuppet< puppet 2.7.18-1 (bullseye)puppet 2.7.18-1 (bullseye)
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet
puppetpuppet

CVSS provenance

nvd3.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW