CVE-2012-1988: Canonical Ubuntu Linux

Medium severity, CVSS 6.0. EPSS: 2.6% chance of exploitation in the next 30 days.

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.04 only; version 11.10 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Fedoraproject Fedora: version 15 only; version 16 only; version 17 only
  • Puppet Puppet: from 2.6.0, before 2.6.15 (fixed in 2.6.15); from 2.7.0, before 2.7.13 (fixed in 2.7.13)
  • Puppet Puppet Enterprise: from 1.2.0, before 2.5.1 (fixed in 2.5.1); version 1.0 only; version 1.1 only

Published 2012-05-29. Last modified 2026-06-16.