CVE-2012-3865
published 2012-08-06CVE-2012-3865: Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when…
PriorityP421low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.88%
77.2th percentile
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.18-1 (bullseye) | puppet 2.7.18-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_ubuntu4.0MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Puppet vulnerable to Path Traversal
ghsa·2017-10-24
CVE-2012-3865 [LOW] CWE-22 Puppet vulnerable to Path Traversal
Puppet vulnerable to Path Traversal
Directory traversal vulnerability in `lib/puppet/reports/store.rb` in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a `..` (dot dot) in a node name.
OSV
Puppet vulnerable to Path Traversal
osv·2017-10-24
CVE-2012-3865 [LOW] Puppet vulnerable to Path Traversal
Puppet vulnerable to Path Traversal
Directory traversal vulnerability in `lib/puppet/reports/store.rb` in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a `..` (dot dot) in a node name.
OSV
CVE-2012-3865: Directory traversal vulnerability in lib/puppet/reports/store
osv·2012-08-06·CVSS 3.5
CVE-2012-3865 [LOW] CVE-2012-3865: Directory traversal vulnerability in lib/puppet/reports/store
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-07-12·CVSS 4.0
CVE-2012-3864 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in Puppet.
It was discovered that Puppet incorrectly handled certain HTTP GET
requests. An attacker could use this flaw with a valid client certificate
to retrieve arbitrary files from the Puppet primary server.
(CVE-2012-3864)
It was discovered that Puppet incorrectly handled Delete requests. If a
Puppet primary server were reconfigured to allow the "Delete" method, an
attacker on an authenticated host could use this flaw to delete arbitrary
files from the Puppet server, leading to a denial of service.
(CVE-2012-3865)
It was discovered that Puppet incorrectly set file permissions on the
last_run_report.yaml file. An attacker could use this flaw to access
sensitive information. This issue only affected Ubuntu 11.
Red Hat
puppet: authenticated clients allowed to delete arbitrary files on the puppet master
vendor_redhat·2012-07-10·CVSS 3.5
CVE-2012-3865 [LOW] puppet: authenticated clients allowed to delete arbitrary files on the puppet master
puppet: authenticated clients allowed to delete arbitrary files on the puppet master
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-3865: puppet - Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet befor...
vendor_debian·2012·CVSS 3.5
CVE-2012-3865 [LOW] CVE-2012-3865: puppet - Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet befor...
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.
Scope: local
bullseye: resolved (fixed in 2.7.18-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2012-3865 puppet: authenticated clients allowed to delete arbitrary files on the puppet master
bugzilla·2012-07-11·CVSS 3.5
CVE-2012-3865 [LOW] CVE-2012-3865 puppet: authenticated clients allowed to delete arbitrary files on the puppet master
CVE-2012-3865 puppet: authenticated clients allowed to delete arbitrary files on the puppet master
From puppet labs: CVE-2012-3865 (Arbitrary file delete/D.O.S on Puppet Master)
A bug in Puppet 2.6.16 and 2.7.17 allows authenticated clients to delete
arbitrary files on the puppet master.
Given a Puppet master with the “Delete” method allowed in auth.conf for an
authenticated host, an attacker on that host can send a specially crafted
Delete request that can cause an arbitrary file deletion on the Puppet master,
potentially causing a denial of service attack. Note that this vulnerability
does *not* exist in Puppet as configured by default; auth.conf must first be
edited to enable deletion.
Resolved in Puppet 2.6.17, 2.7.18
Discussion:
Created puppet tracking bugs for this issue
Affec
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3865/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839131https://github.com/puppetlabs/puppet/commit/554eefc55f57ed2b76e5ee04d8f194d36f6ee67fhttps://github.com/puppetlabs/puppet/commit/d80478208d79a3e6d6cb1fbc525e24817fe8c4c6http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3865/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839131https://github.com/puppetlabs/puppet/commit/554eefc55f57ed2b76e5ee04d8f194d36f6ee67fhttps://github.com/puppetlabs/puppet/commit/d80478208d79a3e6d6cb1fbc525e24817fe8c4c6
2012-08-06
Published