Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown
CVE-2011-3848
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
0
Attacker Value
Unknown
CVE-2011-3869
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
0
Attacker Value
Unknown
CVE-2011-3871
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
0
Attacker Value
Unknown
CVE-2011-3870
Disclosure Date: October 27, 2011 (last updated October 04, 2023)
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
0