CVE-2015-1029
Summary
| CVE | CVE-2015-1029 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-16 16:59:00 UTC |
| Updated | 2019-07-11 13:44:00 UTC |
| Description | The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Puppet | Puppet Enterprise | All | All | All | All |
| Application | Puppet | Puppet Enterprise | All | All | All | All |
| Application | Puppet | Stdlib | 2.1.0 | All | All | All |
| Application | Puppet | Stdlib | 2.1.1 | All | All | All |
| Application | Puppet | Stdlib | 2.1.2 | All | All | All |
| Application | Puppet | Stdlib | 2.1.3 | All | All | All |
| Application | Puppet | Stdlib | 2.2.0 | All | All | All |
| Application | Puppet | Stdlib | 2.2.1 | All | All | All |
| Application | Puppet | Stdlib | 2.3.0 | All | All | All |
| Application | Puppet | Stdlib | 2.3.1 | All | All | All |
| Application | Puppet | Stdlib | 2.3.2 | All | All | All |
| Application | Puppet | Stdlib | 2.3.3 | All | All | All |
| Application | Puppet | Stdlib | 2.4.0 | All | All | All |
| Application | Puppet | Stdlib | 2.5.0 | All | All | All |
| Application | Puppet | Stdlib | 3.0.0 | All | All | All |
| Application | Puppet | Stdlib | 4.1.0 | All | All | All |
| Application | Puppet | Stdlib | 4.2.0 | All | All | All |
| Application | Puppet | Stdlib | 4.2.1 | All | All | All |
| Application | Puppet | Stdlib | 4.2.2 | All | All | All |
| Application | Puppet | Stdlib | 4.3.0 | All | All | All |
| Application | Puppet | Stdlib | 4.3.1 | All | All | All |
| Application | Puppet | Stdlib | 4.3.2 | All | All | All |
| Application | Puppet | Stdlib | 4.4.0 | All | All | All |
| Application | Puppet | Stdlib | 4.5.0 | All | All | All |
| Application | Puppet | Stdlib | 2.1.0 | All | All | All |
| Application | Puppet | Stdlib | 2.1.1 | All | All | All |
| Application | Puppet | Stdlib | 2.1.2 | All | All | All |
| Application | Puppet | Stdlib | 2.1.3 | All | All | All |
| Application | Puppet | Stdlib | 2.2.0 | All | All | All |
| Application | Puppet | Stdlib | 2.2.1 | All | All | All |
| Application | Puppet | Stdlib | 2.3.0 | All | All | All |
| Application | Puppet | Stdlib | 2.3.1 | All | All | All |
| Application | Puppet | Stdlib | 2.3.2 | All | All | All |
| Application | Puppet | Stdlib | 2.3.3 | All | All | All |
| Application | Puppet | Stdlib | 2.4.0 | All | All | All |
| Application | Puppet | Stdlib | 2.5.0 | All | All | All |
| Application | Puppet | Stdlib | 3.0.0 | All | All | All |
| Application | Puppet | Stdlib | 4.1.0 | All | All | All |
| Application | Puppet | Stdlib | 4.2.0 | All | All | All |
| Application | Puppet | Stdlib | 4.2.1 | All | All | All |
| Application | Puppet | Stdlib | 4.2.2 | All | All | All |
| Application | Puppet | Stdlib | 4.3.0 | All | All | All |
| Application | Puppet | Stdlib | 4.3.1 | All | All | All |
| Application | Puppet | Stdlib | 4.3.2 | All | All | All |
| Application | Puppet | Stdlib | 4.4.0 | All | All | All |
| Application | Puppet | Stdlib | 4.5.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA62328 - Puppet Enterprise puppetlabs-stdlib Module Fact Cache Manipulation Vulnerability - Secunia | SECUNIA | secunia.com | |
| CVE-2015-1029 | Puppet Labs | CONFIRM | puppetlabs.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.