Vulnerability Name:

CVE-2011-0528 (CCN-64996)

Assigned:2010-12-01
Published:2010-12-01
Updated:2019-07-10
Summary:Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
3.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2011-0528

Source: CCN
Type: SA43090
Puppet Missing auth.conf Security Issue

Source: MLIST
Type: UNKNOWN
[puppet-users] 20101201 SECURITY: Authorization vulnerability in Puppet 2.6.x

Source: CCN
Type: puppet-users Mailing List Wed, 01 Dec 2010 13:02:00
Authorization vulnerability in Puppet 2.6.x

Source: MLIST
Type: UNKNOWN
[oss-security] 20110127 CVE request: puppet

Source: MLIST
Type: UNKNOWN
[oss-security] 20110127 Re: CVE request: puppet

Source: CCN
Type: OSVDB ID: 70684
Puppet Missing auth.conf Cross-node Authentication Bypass Resource Modification

Source: CCN
Type: Puppet Labs Web site
Puppet

Source: CCN
Type: BID-46050
Puppet Security Bypass Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-1365-1

Source: XF
Type: UNKNOWN
puppet-authconf-security-bypass(64996)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:puppet:puppet:2.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:puppet:puppet:2.6.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:15245
    P
    USN-1365-1 -- Puppet vulnerability
    2014-06-30
    BACK
    puppet puppet 2.6.0
    puppet puppet 2.6.1
    puppet puppet 2.6.2
    puppet puppet 2.6.3
    puppetlabs puppet 2.6.3