CVE-2012-3865: Puppet
Low severity, CVSS 3.5. EPSS: 1.9% chance of exploitation in the next 30 days.
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.
Affected products
- Puppet Puppet: version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; version 2.7.6 only; version 2.7.8 only; …
- Puppet Puppet Enterprise: up to and including 2.5.1
- Puppetlabs Puppet: up to and including 2.7.17; version 2.7.0 only; version 2.7.1 only; up to and including 2.6.16
Published 2012-08-06. Last modified 2026-06-16.