Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款Puppet产品非信任搜索路径漏洞
Vulnerability Description
Puppet等都是美国Puppet实验室开发的产品。Puppet是一套基于客户端/服务器(C/S)架构的配置管理工具;Puppet Enterprise是一个企业版;Facter是一个用于获取客户端系统信息(如主机名、IP地址和操作系统版本等)的包。 多款Puppet产品中存在非信任搜索路径漏洞。当程序运行在Ruby 1.9.1及之前版本上时,本地攻击者可借助当前工作目录中的Trojan horse文件利用该漏洞获取权限。以下产品和版本受到影响:Puppet Enterprise 2.8.7之前2.8版本
CVSS Information
N/A
Vulnerability Type
N/A