Puppet CVE-2012-6120 Insecure File Permissions Vulnerability
BID:58887
Info
Puppet CVE-2012-6120 Insecure File Permissions Vulnerability
| Bugtraq ID: | 58887 |
| Class: | Design Error |
| CVE: |
CVE-2012-6120 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 17 2012 12:00AM |
| Updated: | Aug 28 2013 06:08PM |
| Credit: | Unknown |
| Vulnerable: |
Puppet Labs Puppet 2.6.14 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Puppet CVE-2012-6120 Insecure File Permissions Vulnerability
Puppet is prone to an insecure-file-permissions vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Puppet 2.6.14 and 2.6.17 are vulnerable.
Puppet is prone to an insecure-file-permissions vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Puppet 2.6.14 and 2.6.17 are vulnerable.
Exploit / POC
Puppet CVE-2012-6120 Insecure File Permissions Vulnerability
An attacker requires local interactive access to the affected application to exploit this issue.
An attacker requires local interactive access to the affected application to exploit this issue.
References
Puppet CVE-2012-6120 Insecure File Permissions Vulnerability
References:
References:
- Puppet Homepage (Puppet Labs)