CVE-2017-10690

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:satellite:6.4:*:*:*:*:*:*:*

History

21 Nov 2024, 03:06

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2018:2927 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2018:2927 - Third Party Advisory
References () https://puppet.com/security/cve/CVE-2017-10690 - Vendor Advisory () https://puppet.com/security/cve/CVE-2017-10690 - Vendor Advisory

24 Jan 2022, 16:46

Type Values Removed Values Added
CPE cpe:2.3:a:puppet:puppet:*:*:*:*:enterprise:*:*:* cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

Information

Published : 2018-02-09 20:29

Updated : 2024-11-21 03:06


NVD link : CVE-2017-10690

Mitre link : CVE-2017-10690

CVE.ORG link : CVE-2017-10690


JSON object : View

Products Affected

puppet

  • puppet
  • puppet_enterprise

redhat

  • satellite
CWE
CWE-269

Improper Privilege Management