CVE-2012-6120
published 2013-04-10CVE-2012-6120: Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.39%
31.3th percentile
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.6.4-2 (bullseye) | puppet 2.6.4-2 (bullseye) |
| puppet | puppet | >= 0 < 2.6.4-2 | 2.6.4-2 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Puppet: Directory /var/log/puppet is world readable
vendor_redhat·2012-09-17·CVSS 2.1
CVE-2012-6120 [LOW] Puppet: Directory /var/log/puppet is world readable
Puppet: Directory /var/log/puppet is world readable
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
Package: puppet (Red Hat Enterprise MRG 1) - Affected
Package: puppet (Red Hat Subscription Asset Manager) - Affected
Debian
CVE-2012-6120: puppet - Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with wo...
vendor_debian·2012·CVSS 2.1
CVE-2012-6120 [LOW] CVE-2012-6120: puppet - Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with wo...
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
Scope: local
bullseye: resolved (fixed in 2.6.4-2)
GHSA
GHSA-mph7-5pc9-hg5q: Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive
ghsa_unreviewed·2022-05-17
CVE-2012-6120 [LOW] GHSA-mph7-5pc9-hg5q: Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
OSV
CVE-2012-6120: Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive
osv·2013-04-10·CVSS 2.1
CVE-2012-6120 [LOW] CVE-2012-6120: Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6120 Puppet: Directory /var/log/puppet is world readable [epel-all]
bugzilla·2013-02-07·CVSS 2.1
CVE-2012-6120 [LOW] CVE-2012-6120 Puppet: Directory /var/log/puppet is world readable [epel-all]
CVE-2012-6120 Puppet: Directory /var/log/puppet is world readable [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2012-6120 Puppet: Directory /var/log/puppet is world readable
bugzilla·2013-02-07·CVSS 2.1
CVE-2012-6120 [LOW] CVE-2012-6120 Puppet: Directory /var/log/puppet is world readable
CVE-2012-6120 Puppet: Directory /var/log/puppet is world readable
/var/log/puppet is world readable and may contain sensitive information
Also the files contained within are world readable.
Version-Release number of selected component (if applicable):
puppet-2.6.14-1.el6.noarch
puppet-2.6.17-2.el6.noarch
How reproducible:
drwxr-xr-x. 2 puppet puppet 4096 Mar 8 16:35 /var/log/puppet
Discussion:
Created puppet tracking bugs for this issue
Affects: epel-all [bug 908915]
---
(In reply to comment #0)
> Lukas Zapletal reports:
>
> /var/log/puppet is world readable and may contain sensitive information
FYI that was EPEL bug https://bugzilla.redhat.com/show_bug.cgi?id=857930
---
And this was a bug in the build system, not in the packaging. A recent update and build without change to
2013-04-10
Published