CVE-2017-10689: Medium severity Puppet Puppet vulnerability
Published Feb 7, 2018
·Updated
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
Other sources
In puppet before versions 4.10.10 and 5.3.4, when unpacking tarballs with minitar in lib/puppet/moduletool/tar/mini.rb, files are unpacked with the same permissions as in the tarball allowing for files with unsafe permissions.
Upstream Advisory:
https://puppet.com/security/cve/CVE-2017-10689
Upstream Issue:
https://tickets.puppetlabs.com/browse/PUP-7866
Upstream Commit:
https://github.com/puppetlabs/puppet/commit/17d9e02da3882e44c1876e2805cf9708481715ee
— Red Hat
Affected Software
9 affected componentsFixes available
redhat/puppet<4.10.10
4.10.10
redhat/puppet<5.3.4
5.3.4
debian/puppet
5.5.22-2
Puppet Puppet<5.3.4
Puppet Puppet>=1.10.0<1.10.10
Puppet Puppet Enterprise<2016.4.10
Puppet Puppet Enterprise>=2017.1.0<2017.3.4
Canonical Ubuntu Linux=14.04
redhat Satellite=6.4
Remediation
Event History
Feb 9, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:24 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:00 PM
RemedyDescriptionSeverityAffected Software