PT-2013-1225 · Red Hat+1 · Red Hat Openstack+1

Published

2013-04-10

·

Updated

2013-08-23

·

CVE-2012-6120

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat OpenStack versions Essex and Folsom Puppet versions prior to 2.7.23
Description The issue allows local users to obtain sensitive information, such as Puppet log files, due to the world-readable permissions of the /var/log/puppet directory. Additionally, multiple vulnerabilities in the Puppet package can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely by an authenticated attacker.
Recommendations For Red Hat OpenStack versions Essex and Folsom, consider changing the permissions of the /var/log/puppet directory to restrict access to sensitive information. For Puppet versions prior to 2.7.23, update to version 2.7.23 or later to resolve the vulnerabilities.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09724
CVE-2012-6120
DLA-29-1
RHSA-2013:0710

Affected Products

Puppet
Red Hat Openstack