CVE-2012-1986: Low severity puppet vulnerability
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1986?
CVE-2012-1986 has been rated as a medium severity vulnerability due to the potential for unauthorized file access.
How do I fix CVE-2012-1986?
To fix CVE-2012-1986, you should upgrade to Puppet versions 2.6.15, 2.7.13, or later.
What systems are affected by CVE-2012-1986?
CVE-2012-1986 affects Puppet versions 2.6.x prior to 2.6.15 and 2.7.x prior to 2.7.13, as well as Puppet Enterprise users of specific early versions.
Can remote authenticated users exploit CVE-2012-1986?
Yes, remote authenticated users with an authorized SSL key and necessary permissions can exploit CVE-2012-1986 to read arbitrary files.
What type of attack is associated with CVE-2012-1986?
CVE-2012-1986 is associated with a symlink attack that allows unauthorized file access.