CVE-2011-0528: Medium severity puppet vulnerability
Published Feb 17, 2014
·Updated
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
Affected Software
5 affected componentsFixes available
rubygems/puppet>=2.6.0<=2.6.3
2.6.4
puppet Puppet=2.6.0
puppet Puppet=2.6.1
puppet Puppet=2.6.2
puppet Puppet=2.6.3
Event History
Feb 17, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·12:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-0528?
CVE-2011-0528 is classified as a medium severity vulnerability due to inadequate access restrictions.
2
How do I fix CVE-2011-0528?
To fix CVE-2011-0528, upgrade Puppet to version 2.6.4 or later.
3
Which versions of Puppet are affected by CVE-2011-0528?
CVE-2011-0528 affects Puppet versions 2.6.0 through 2.6.3.
4
Can CVE-2011-0528 be exploited remotely?
Yes, CVE-2011-0528 can be exploited by remote authenticated Puppet nodes.
5
What type of information can be accessed due to CVE-2011-0528?
CVE-2011-0528 allows remote authenticated nodes to read or modify the resources of other nodes.