CVE-2012-1988
Summary
| CVE | CVE-2012-1988 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-05-29 20:55:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| USN-1419-1: Puppet vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Bug #13518: file bucket request can execute arbitrary commands as puppet master - Puppet - Puppet Labs | af854a3a-2127-422b-91ae-364da2661108 | projects.puppetlabs.com | Broken Link, Vendor Advisory |
| Release Notes - Puppet - Puppet Labs | af854a3a-2127-422b-91ae-364da2661108 | projects.puppetlabs.com | Broken Link |
| www.osvdb.org/81309 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| [SECURITY] Fedora 15 Update: puppet-2.6.16-1.fc15 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-2451-1 puppet | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| hermes.opensuse.org/messages/15087408 | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | Broken Link |
| hermes.opensuse.org/messages/14523305 | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | Broken Link |
| CVE-2012-1988 | Puppet Labs | af854a3a-2127-422b-91ae-364da2661108 | puppetlabs.com | Broken Link, Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| [SECURITY] Fedora 17 Update: puppet-2.7.13-1.fc17 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Puppet Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 16 Update: puppet-2.6.16-1.fc16 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996702 Rubygems (Rubygems) Security Update for puppet (GHSA-6xxq-j39w-g3f6)