Vulnerability Name:
CVE-2015-1426 (CCN-102764)
Assigned:
2015-01-30
Published:
2015-01-30
Updated:
2019-07-11
Summary:
Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
2.1 Low
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
)
1.6 Low
(Temporal CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
5.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
)
3.7 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-200
Vulnerability Consequences:
Obtain Information
References:
Source: MITRE
Type: CNA
CVE-2015-1426
Source: CONFIRM
Type: Vendor Advisory
http://puppetlabs.com/security/cve/cve-2015-1426
Source: XF
Type: UNKNOWN
puppetlabs-cve20151426-info-disc(102764)
Source: CCN
Type: PuppetLabs CVE-2015-1426
CVE-2015-1426 - Potential sensitive information leakage in Facterâ??s Amazon EC2 metadata facts handling
Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-1426
Vulnerable Configuration:
Configuration 1
:
cpe:/a:puppet:facter:1.6.0:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.1:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.1:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.1:rc3:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.1:rc4:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.2:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.3:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.4:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.5:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.6:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.6:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.7:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.8:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.9:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.10:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.11:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.12:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.12:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.13:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.14:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.15:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.16:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.17:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.18:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.0:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.0:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.1:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.2:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.3:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.4:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.5:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.5:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.0:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.0:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.0:rc3:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.0:rc4:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.1:rc1:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.1:rc2:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.1:rc3:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.1:rc4:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.2:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.1.0:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.2.0:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.3.0:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.4.0:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.1:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.2:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.3:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.4:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.5:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.6:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.7:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.8:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.9:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.10:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.11:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.12:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.13:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.14:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.15:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.17:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.6.18:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.0:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.1:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.2:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.3:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.4:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.5:-:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:1.7.6:*:*:*:*:*:*:*
OR
cpe:/a:puppet:facter:2.0.1:-:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.opensuse.security:def:20151426
V
CVE-2015-1426
2022-05-20
oval:org.opensuse.security:def:32242
P
Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
2021-12-14
oval:org.opensuse.security:def:32243
P
Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
2021-12-14
oval:org.opensuse.security:def:30158
P
Security update for the Linux Kernel (Important)
2021-12-06
oval:org.opensuse.security:def:33749
P
Security update for webkit2gtk3 (Important)
2021-12-01
oval:org.opensuse.security:def:33733
P
Security update for transfig (Important)
2021-10-29
oval:org.opensuse.security:def:33028
P
Security update for git (Low)
2021-10-20
oval:org.opensuse.security:def:30139
P
Security update for postgresql10 (Important)
2021-10-20
oval:org.opensuse.security:def:33005
P
Security update for gtk-vnc (Moderate)
2021-09-16
oval:org.opensuse.security:def:33710
P
Security update for file (Important)
2021-09-02
oval:org.opensuse.security:def:29409
P
Security update for fetchmail (Moderate)
2021-08-18
oval:org.opensuse.security:def:32966
P
Security update for curl (Moderate)
2021-07-21
oval:org.opensuse.security:def:29398
P
Security update for the Linux Kernel (Important)
2021-07-20
oval:org.opensuse.security:def:29397
P
Security update for MozillaFirefox (Important)
2021-07-16
oval:org.opensuse.security:def:30100
P
Security update for openexr (Important)
2021-06-24
oval:org.opensuse.security:def:30202
P
Security update for libwebp (Critical)
2021-06-02
oval:org.opensuse.security:def:32917
P
Security update for python3 (Important)
2021-05-17
oval:org.opensuse.security:def:33637
P
Security update for sudo (Important)
2021-04-20
oval:org.opensuse.security:def:33790
P
Security update for MozillaFirefox (Important)
2021-03-31
oval:org.opensuse.security:def:28962
P
Security update for nghttp2 (Important)
2021-03-24
oval:org.opensuse.security:def:30051
P
Security update for openssl (Moderate)
2021-03-24
oval:org.opensuse.security:def:29481
P
Security update for the Linux Kernel (Important)
2021-03-09
oval:org.opensuse.security:def:34036
P
Security update for openssl-1_0_0 (Moderate)
2021-03-08
oval:org.opensuse.security:def:32254
P
Security update for openvswitch (Important)
2021-02-12
oval:org.opensuse.security:def:33072
P
Security update for openvswitch (Important)
2021-02-12
oval:org.opensuse.security:def:28923
P
Security update for MozillaFirefox (Important)
2021-01-29
oval:org.opensuse.security:def:28874
P
Security update for clamav (Important)
2020-12-22
oval:org.opensuse.security:def:33879
P
Security update for openssl-1_0_0 (Important)
2020-12-09
oval:org.opensuse.security:def:33407
P
Security update for SUSE Manager Client Tools (Critical)
2020-12-01
oval:org.opensuse.security:def:28668
P
Security update for MozillaFirefox
2020-12-01
oval:org.opensuse.security:def:29697
P
Security update for facter (Moderate)
2020-12-01
oval:org.opensuse.security:def:29700
P
Security update for file-roller (Moderate)
2020-12-01
oval:org.opensuse.security:def:32331
P
Security update for samba (Moderate)
2020-12-01
oval:org.opensuse.security:def:33408
P
Security update for cobbler (Moderate)
2020-12-01
oval:org.opensuse.security:def:34094
P
Security update for microcode_ctl (Important)
2020-12-01
oval:org.opensuse.security:def:28232
P
Security update for libvirt (Moderate)
2020-12-01
oval:org.opensuse.security:def:28820
P
Security update for Python
2020-12-01
oval:org.opensuse.security:def:29757
P
Security update for ghostscript-library (Moderate)
2020-12-01
oval:org.opensuse.security:def:30840
P
Security update for curl (Moderate)
2020-12-01
oval:org.opensuse.security:def:32466
P
Security update for xorg-x11-libs (Moderate)
2020-12-01
oval:org.opensuse.security:def:33419
P
Security update for NetworkManager-gnome
2020-12-01
oval:org.opensuse.security:def:34143
P
Security update for openldap2 (Important)
2020-12-01
oval:org.opensuse.security:def:28233
P
Security update for libvirt (Moderate)
2020-12-01
oval:org.opensuse.security:def:29843
P
Security update for Linux kernel
2020-12-01
oval:org.opensuse.security:def:30877
P
Security update for facter (Moderate)
2020-12-01
oval:org.opensuse.security:def:32560
P
libopenssl0_9_8 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:33501
P
Security update for Mozilla XULrunner
2020-12-01
oval:org.opensuse.security:def:34182
P
Security update for openssl1 (Important)
2020-12-01
oval:org.opensuse.security:def:28244
P
Security update for libxml2 (Important)
2020-12-01
oval:org.opensuse.security:def:29996
P
Security update for libtirpc, rpcbind (Important)
2020-12-01
oval:org.opensuse.security:def:32617
P
xorg-x11 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:34207
P
Security update for perl-DBI (Important)
2020-12-01
oval:org.opensuse.security:def:28311
P
Security update for openssl (Important)
2020-12-01
oval:org.opensuse.security:def:32704
P
libapr1 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:34251
P
Security update for postgresql10 (Important)
2020-12-01
oval:org.opensuse.security:def:28442
P
Security update for xen (Important)
2020-12-01
oval:org.opensuse.security:def:28979
P
Security update for strongswan (Moderate)
2020-12-01
oval:org.opensuse.security:def:32860
P
findutils on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:34889
P
Security update for curl (Important)
2020-12-01
oval:org.opensuse.security:def:28527
P
Security update for wget (Moderate)
2020-12-01
oval:org.opensuse.security:def:29023
P
Security update for LibVNCServer (Important)
2020-12-01
oval:org.opensuse.security:def:34929
P
Security update for facter (Moderate)
2020-12-01
oval:org.opensuse.security:def:28584
P
Security update for libvirt
2020-12-01
oval:org.opensuse.security:def:29661
P
Security update for curl (Moderate)
2020-12-01
oval:org.opensuse.security:def:29613
P
Security update for bind (Critical)
2020-12-01
oval:com.ubuntu.bionic:def:201514260000000
V
CVE-2015-1426 on Ubuntu 18.04 LTS (bionic) - low.
2015-02-23
oval:com.ubuntu.artful:def:20151426000
V
CVE-2015-1426 on Ubuntu 17.10 (artful) - low.
2015-02-23
oval:com.ubuntu.trusty:def:20151426000
V
CVE-2015-1426 on Ubuntu 14.04 LTS (trusty) - low.
2015-02-23
oval:com.ubuntu.xenial:def:201514260000000
V
CVE-2015-1426 on Ubuntu 16.04 LTS (xenial) - low.
2015-02-23
oval:com.ubuntu.bionic:def:20151426000
V
CVE-2015-1426 on Ubuntu 18.04 LTS (bionic) - low.
2015-02-23
oval:com.ubuntu.xenial:def:20151426000
V
CVE-2015-1426 on Ubuntu 16.04 LTS (xenial) - low.
2015-02-23
oval:com.ubuntu.disco:def:201514260000000
V
CVE-2015-1426 on Ubuntu 19.04 (disco) - low.
2015-02-23
oval:com.ubuntu.cosmic:def:20151426000
V
CVE-2015-1426 on Ubuntu 18.10 (cosmic) - low.
2015-02-23
oval:com.ubuntu.cosmic:def:201514260000000
V
CVE-2015-1426 on Ubuntu 18.10 (cosmic) - low.
2015-02-23
oval:com.ubuntu.precise:def:20151426000
V
CVE-2015-1426 on Ubuntu 12.04 LTS (precise) - low.
2015-02-23
BACK
puppet
facter 1.6.0
puppet
facter 1.6.1 rc1
puppet
facter 1.6.1 rc2
puppet
facter 1.6.1 rc3
puppet
facter 1.6.1 rc4
puppet
facter 1.6.2 rc1
puppet
facter 1.6.3 rc1
puppet
facter 1.6.4 rc1
puppet
facter 1.6.5 rc1
puppet
facter 1.6.6 rc1
puppet
facter 1.6.6 rc2
puppet
facter 1.6.7 rc1
puppet
facter 1.6.8 rc1
puppet
facter 1.6.9 rc1
puppet
facter 1.6.10 rc1
puppet
facter 1.6.11 rc1
puppet
facter 1.6.12 rc1
puppet
facter 1.6.12 rc2
puppet
facter 1.6.13 rc1
puppet
facter 1.6.14 rc1
puppet
facter 1.6.15 rc1
puppet
facter 1.6.16
puppet
facter 1.6.17 rc1
puppet
facter 1.6.18 rc1
puppet
facter 1.7.0 rc1
puppet
facter 1.7.0 rc2
puppet
facter 1.7.1 rc1
puppet
facter 1.7.2 rc1
puppet
facter 1.7.3 rc1
puppet
facter 1.7.4 rc1
puppet
facter 1.7.5 rc1
puppet
facter 1.7.5 rc2
puppet
facter 2.0.0 rc1
puppet
facter 2.0.0 rc2
puppet
facter 2.0.0 rc3
puppet
facter 2.0.0 rc4
puppet
facter 2.0.1 rc1
puppet
facter 2.0.1 rc2
puppet
facter 2.0.1 rc3
puppet
facter 2.0.1 rc4
puppet
facter 2.0.2
puppet
facter 2.1.0
puppet
facter 2.2.0
puppet
facter 2.3.0
puppet
facter 2.4.0
puppetlabs
facter 1.6.1
puppetlabs
facter 1.6.2
puppetlabs
facter 1.6.3
puppetlabs
facter 1.6.4
puppetlabs
facter 1.6.5
puppetlabs
facter 1.6.6
puppetlabs
facter 1.6.7
puppetlabs
facter 1.6.8
puppetlabs
facter 1.6.9
puppetlabs
facter 1.6.10
puppetlabs
facter 1.6.11
puppetlabs
facter 1.6.12
puppetlabs
facter 1.6.13
puppetlabs
facter 1.6.14
puppetlabs
facter 1.6.15
puppetlabs
facter 1.6.17
puppetlabs
facter 1.6.18
puppetlabs
facter 1.7.0
puppetlabs
facter 1.7.1
puppetlabs
facter 1.7.2
puppetlabs
facter 1.7.3
puppetlabs
facter 1.7.4
puppetlabs
facter 1.7.5
puppetlabs
facter 1.7.6
puppetlabs
facter 2.0.1