CVE

Id
57109  
CVE No.
CVE-2012-3866  
Status
Candidate  
Description
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.  
Phase
Assigned (20120706)  
Votes
None (candidate not yet proposed)  
Comments