CVE-2012-3866
published 2012-08-06CVE-2012-3866: lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.48%
38.3th percentile
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.18-1 (bullseye) | puppet 2.7.18-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.18-1 | 2.7.18-1 |
| puppet | puppet | >= 2.7.0 < 2.7.18 | 2.7.18 |
| puppet | puppet_enterprise | <= 2.5.1 | — |
| puppetlabs | puppet | <= 2.7.17 | — |
| puppetlabs | puppet | — | — |
| puppetlabs | puppet | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu4.0MEDIUM
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-07-12·CVSS 4.0
CVE-2012-3864 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in Puppet.
It was discovered that Puppet incorrectly handled certain HTTP GET
requests. An attacker could use this flaw with a valid client certificate
to retrieve arbitrary files from the Puppet primary server.
(CVE-2012-3864)
It was discovered that Puppet incorrectly handled Delete requests. If a
Puppet primary server were reconfigured to allow the "Delete" method, an
attacker on an authenticated host could use this flaw to delete arbitrary
files from the Puppet server, leading to a denial of service.
(CVE-2012-3865)
It was discovered that Puppet incorrectly set file permissions on the
last_run_report.yaml file. An attacker could use this flaw to access
sensitive information. This issue only affected Ubuntu 11.
Debian
CVE-2012-3866: puppet - lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise befo...
vendor_debian·2012·CVSS 2.1
CVE-2012-3866 [LOW] CVE-2012-3866: puppet - lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise befo...
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
Scope: local
bullseye: resolved (fixed in 2.7.18-1)
OSV
Puppet allows local users to obtain sensitive configuration information
osv·2017-10-24
CVE-2012-3866 [LOW] Puppet allows local users to obtain sensitive configuration information
Puppet allows local users to obtain sensitive configuration information
`lib/puppet/defaults.rb` in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for `last_run_report.yaml`, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
GHSA
Puppet allows local users to obtain sensitive configuration information
ghsa·2017-10-24
CVE-2012-3866 [LOW] Puppet allows local users to obtain sensitive configuration information
Puppet allows local users to obtain sensitive configuration information
`lib/puppet/defaults.rb` in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for `last_run_report.yaml`, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
OSV
CVE-2012-3866: lib/puppet/defaults
osv·2012-08-06·CVSS 2.1
CVE-2012-3866 [LOW] CVE-2012-3866: lib/puppet/defaults
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2012-3866 puppet: information leak via world readable last_run_report.yaml
bugzilla·2012-07-11·CVSS 2.1
CVE-2012-3866 [LOW] CVE-2012-3866 puppet: information leak via world readable last_run_report.yaml
CVE-2012-3866 puppet: information leak via world readable last_run_report.yaml
From puppet labs: CVE-2012-3866 (last_run_report.yaml is world readable)
A bug in Puppet 2.7.17 leaves last_run_report.yaml world readable.
The most recent Puppet run report is stored on the Puppet master with
world-readable permissions. The report file contains the context diffs of any
changes to configuration on an agent, which may contain sensitive information
that an attacker can then access. The last run report is overwritten with
every Puppet run.
Note: This only affects the 2.7 series of Puppet.
Resolved in Puppet 2.7.18
Discussion:
Created puppet tracking bugs for this issue
Affects: fedora-17 [bug 839168]
---
External Reference:
http://puppetlabs.com/security/cve/cve-2012-3866/
---
Upstream
http://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3866/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839135https://github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3fhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3866/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839135https://github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3f
2012-08-06
Published