{"id":"GHSA-8jxj-9r5f-w3m2","summary":"Puppet allows local users to obtain sensitive configuration information","details":"`lib/puppet/defaults.rb` in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for `last_run_report.yaml`, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.","aliases":["CVE-2012-3866"],"modified":"2024-11-29T05:40:25.117232Z","published":"2017-10-24T18:33:37Z","database_specific":{"cwe_ids":[],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:25:49Z","nvd_published_at":"2012-08-06T16:55:06Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-3866"},{"type":"WEB","url":"https://github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3f"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=839135"},{"type":"PACKAGE","url":"https://github.com/puppetlabs/puppet"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2012-3866.yml"},{"type":"WEB","url":"https://www.puppet.com/security/cve/cve-2012-3866-lastrunreportyaml-world-readable"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2012-07/msg00036.html"},{"type":"WEB","url":"http://puppetlabs.com/security/cve/cve-2012-3866"},{"type":"WEB","url":"http://www.debian.org/security/2012/dsa-2511"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-1506-1"}],"affected":[{"package":{"name":"puppet","ecosystem":"RubyGems","purl":"pkg:gem/puppet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.7.18"}]}],"versions":["2.7.1","2.7.11","2.7.12","2.7.13","2.7.14","2.7.16","2.7.17","2.7.3","2.7.4","2.7.5","2.7.6","2.7.8","2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-8jxj-9r5f-w3m2/GHSA-8jxj-9r5f-w3m2.json"}}],"schema_version":"1.9.0"}