CVE-2011-3848: Path Traversal
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3848?
CVE-2011-3848 has been assigned a medium severity rating due to the potential for unauthorized access to sensitive files.
How do I fix CVE-2011-3848?
To fix CVE-2011-3848, upgrade Puppet to version 2.6.10 or 2.7.4 or later.
Which versions of Puppet are affected by CVE-2011-3848?
Puppet versions 2.6.0 through 2.6.9 and 2.7.0 through 2.7.3 are affected by CVE-2011-3848.
What type of vulnerability is CVE-2011-3848?
CVE-2011-3848 is a directory traversal vulnerability that allows attackers to write data to arbitrary locations.
Can CVE-2011-3848 be exploited remotely?
Yes, CVE-2011-3848 can be exploited remotely by attackers using crafted requests.