QID 996742
Date Published: 2024-01-17
QID 996742: Rubygems (Rubygems) Security Update for puppet (GHSA-9pvx-fwwh-w289)
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9pvx-fwwh-w289 for updates and patch information.
Vendor References
- GHSA-9pvx-fwwh-w289 -
github.com/advisories/GHSA-9pvx-fwwh-w289
CVEs related to QID 996742
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9pvx-fwwh-w289 | puppet |
|