Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Puppet任意文件覆盖漏洞
Vulnerability Description
Puppet是一种开源的自动化系统配置管理工具,利用它IT组织可以对配置服务进行编码,从而形成一种管理规则,随后系统框架会对其进行审查并强制实施。 Puppet 存在任意文件覆盖漏洞。本地攻击者可以借助(1) /tmp/daemonout、(2) /tmp/puppetdoc.txt、 (3) /tmp/puppetdoc.tex、 或 (4) /tmp/puppetdoc.aux 临时文件的符号链接攻击,导致任意文件覆盖。
CVSS Information
N/A
Vulnerability Type
N/A