cbcvebase.
CVE-2017-10689
published 2018-02-09

CVE-2017-10689: In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this…

medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianpuppet< puppet 5.4.0-1 (bullseye)puppet 5.4.0-1 (bullseye)
puppetpuppet< 5.3.45.3.4
puppetpuppet>= 0 < 5.4.0-15.4.0-1
puppetpuppet>= 0 < 4.10.104.10.10
puppetpuppet>= 0 < 3.8.5-2ubuntu0.1+esm13.8.5-2ubuntu0.1+esm1
puppetpuppet>= 1.10.0 < 1.10.101.10.10
puppetpuppet>= 5.0.0 < 5.3.45.3.4
puppetpuppet_agent
puppetpuppet_enterprise< 2016.4.102016.4.10
puppetpuppet_enterprise
puppetpuppet_enterprise>= 2017.1.0 < 2017.3.42017.3.4
redhatsatellite

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv5.5MEDIUM