PT-2013-1225 · Red Hat+1 · Red Hat Openstack+1
Published
2013-04-10
·
Updated
2013-08-23
·
CVE-2012-6120
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat OpenStack versions Essex and Folsom
Puppet versions prior to 2.7.23
Description
The issue allows local users to obtain sensitive information, such as Puppet log files, due to the world-readable permissions of the /var/log/puppet directory. Additionally, multiple vulnerabilities in the Puppet package can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely by an authenticated attacker.
Recommendations
For Red Hat OpenStack versions Essex and Folsom, consider changing the permissions of the /var/log/puppet directory to restrict access to sensitive information.
For Puppet versions prior to 2.7.23, update to version 2.7.23 or later to resolve the vulnerabilities.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Puppet
Red Hat Openstack