QID 996702

Date Published: 2024-01-15

QID 996702: Rubygems (Rubygems) Security Update for puppet (GHSA-6xxq-j39w-g3f6)

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    Refer to Github security advisory GHSA-6xxq-j39w-g3f6 for updates and patch information.
    Vendor References

    CVEs related to QID 996702

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6xxq-j39w-g3f6 puppet URL Logo github.com/advisories/GHSA-6xxq-j39w-g3f6