|
|
| |
|
| |
puppet: multiple vulnerabilities
| Package(s): | puppet |
CVE #(s): | CVE-2012-3864
CVE-2012-3865
CVE-2012-3866
CVE-2012-3867
|
| Created: | July 13, 2012 |
Updated: | August 13, 2012 |
| Description: |
From the Debian advisory:
CVE-2012-3864: Authenticated clients could read arbitrary files on the puppet master.
CVE-2012-3865: Authenticated clients could delete arbitrary files on the puppet master.
CVE-2012-3866: The report of the most recent Puppet run was stored with world-readable permissions, resulting in information disclosure.
CVE-2012-3867: Agent hostnames were insufficiently validated. |
| Alerts: |
|
( Log in to post comments)
|
|
|