CVE-2017-10690
published 2018-02-09CVE-2017-10690: In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was…
PriorityP430medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.02%
59.6th percentile
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet | < 5.3.4 | 5.3.4 |
| puppet | puppet | >= 0 < 3.4.3-1ubuntu1.3 | 3.4.3-1ubuntu1.3 |
| puppet | puppet | >= 0 < 3.8.5-2ubuntu0.1 | 3.8.5-2ubuntu0.1 |
| puppet | puppet_agent | — | — |
| puppet | puppet_enterprise | < 2017.3.4 | 2017.3.4 |
| puppet | puppet_enterprise | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5m5-pcq8-cjj7: In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from
ghsa_unreviewed·2022-05-13
CVE-2017-10690 [MEDIUM] CWE-269 GHSA-v5m5-pcq8-cjj7: In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
OSV
CVE-2017-10690: In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from
osv·2018-02-09·CVSS 6.5
CVE-2017-10690 [MEDIUM] CVE-2017-10690: In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
Red Hat
puppet: Environment leakage in puppet-agent
vendor_redhat·2018-02-05·CVSS 6.5
CVE-2017-10690 [MEDIUM] CWE-203 puppet: Environment leakage in puppet-agent
puppet: Environment leakage in puppet-agent
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
Statement: This issue affects the versions of puppet-agent as shipped with Red Hat Enterprise Satellite 6.3 and later. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Debian
CVE-2017-10690: puppet - In previous versions of Puppet Agent it was possible for the agent to retrieve f...
vendor_debian·2017·CVSS 6.5
CVE-2017-10690 [MEDIUM] CVE-2017-10690: puppet - In previous versions of Puppet Agent it was possible for the agent to retrieve f...
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
2018-02-09
Published