CVE-2014-3249: Infoleak
Published Jun 17, 2014
·Updated
Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.
Affected Software
7 affected components
puppet Puppet Enterprise=2.8.0
puppet Puppet Enterprise=2.8.1
puppet Puppet Enterprise=2.8.2
puppet Puppet Enterprise=2.8.3
puppet Puppet Enterprise=2.8.4
puppet Puppet Enterprise=2.8.5
puppet Puppet Enterprise=2.8.6
Event History
Jun 17, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3249?
CVE-2014-3249 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3249?
To fix CVE-2014-3249, upgrade Puppet Enterprise to version 2.8.7 or later.
3
What type of attack does CVE-2014-3249 allow?
CVE-2014-3249 allows remote attackers to obtain sensitive information through manipulating node visibility.
4
Which versions of Puppet Enterprise are affected by CVE-2014-3249?
Puppet Enterprise versions 2.8.0 to 2.8.6 are affected by CVE-2014-3249.
5
Is there a public exploit available for CVE-2014-3249?
As of now, there is no public exploit specifically detailed for CVE-2014-3249.