CVE-2011-3871: Medium severity puppet vulnerability
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
Other sources
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3871?
CVE-2011-3871 is considered a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2011-3871?
To fix CVE-2011-3871, upgrade Puppet to version 2.7.5, 2.6.11, or any version more recent than 0.25.6.
Which versions of Puppet are affected by CVE-2011-3871?
CVE-2011-3871 affects Puppet versions 2.7.x before 2.7.5, 2.6.x before 2.6.11, and all versions of 0.25.x.
What are the risks associated with CVE-2011-3871?
The risks associated with CVE-2011-3871 include the possibility of local users executing arbitrary Puppet code or modifying files unexpectedly.
Can I still use Puppet if I have CVE-2011-3871?
While you can use Puppet with CVE-2011-3871, it is strongly advised to update to a secure version to avoid exploitation of this vulnerability.