Permissions, Privileges, and Access Controls in Puppet Enterprise and Puppet Agent - CVE-2013-4956
Published: August 21, 2013 / Updated: August 10, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were used when the modules were originally built, which might allow local users to read or modify those modules depending on the original permissions.
Affected software
Puppet Agent
Amazon Linux AMI