Synced 18 Jun 2026 05:58 UTC Account
← All products

CVE-2012-1986

LOW severity · CVSS 2.1 · CWE-264
2.1CVSS LOW

Summary

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)1%

AV:N/AC:H/Au:S/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.