CVE-2017-2298: Input Validation
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "pub.pem".
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2298?
CVE-2017-2298 has been classified with a severity level that could lead to unauthorized file write vulnerability.
How do I fix CVE-2017-2298?
To fix CVE-2017-2298, upgrade to version 0.5.1 or later of the mcollective-sshkey-security plugin.
What software is affected by CVE-2017-2298?
CVE-2017-2298 affects versions of the mcollective-sshkey-security plugin prior to 0.5.1 used with Puppet.
What kind of threat does CVE-2017-2298 pose?
CVE-2017-2298 poses a threat of arbitrary file write on the client, potentially leading to further exploits.
Can CVE-2017-2298 be exploited remotely?
Yes, CVE-2017-2298 can be exploited remotely if an attacker has control of the server.