CVE-2014-3248: Medium severity puppetlabs facter vulnerability
Last updated 24 July 2024
Other sources
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operatingsystem.rb, (2) Win32API.rb, (3) Win32API.so, (4) safeyaml.rb, (5) safeyaml/deep.rb, or (6) safeyaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3248?
CVE-2014-3248 is considered a moderate severity vulnerability as it allows local users to gain privileges within the affected software.
How do I fix CVE-2014-3248?
To fix CVE-2014-3248, upgrade the affected software to the recommended versions such as Puppet Enterprise 2.8.7 or newer.
Which versions are affected by CVE-2014-3248?
CVE-2014-3248 affects Puppet Enterprise versions prior to 2.8.7, Puppet versions before 2.7.26 and 3.x before 3.6.2, and specific versions of Facter, Hiera, and MCollective.
Who is affected by CVE-2014-3248?
Users running vulnerable versions of Puppet Enterprise, Puppet, Facter, Hiera, and MCollective, particularly with Ruby 1.9.1 or earlier are affected by CVE-2014-3248.
What is the nature of the vulnerability in CVE-2014-3248?
CVE-2014-3248 is an untrusted search path vulnerability that can permit local users to execute arbitrary code with higher privileges.