CVE-2011-3870 – puppet
Package
Manager: gem
Name: puppet
Vulnerable Version: >=2.7.0 <2.7.5 || >=0 <2.6.11
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00033 pctl0.07759
Details
Puppet allows local users to modify the permissions of arbitrary files Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
Metadata
Created: 2022-05-14T00:56:54Z
Modified: 2024-01-16T21:28:46Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qh3g-27jf-3j54/GHSA-qh3g-27jf-3j54.json
CWE IDs: ["CWE-59"]
Alternative ID: GHSA-qh3g-27jf-3j54
Finding: F076
Auto approve: 1