Synced 20 Jun 2026 01:50 UTC Account
← All products

CVE-2012-3866

LOW severity · CVSS 2.1 · CWE-264
2.1CVSS LOW

Summary

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%

AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3f ↗