CVE-2012-3866: Puppet
Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
Affected products
- Puppet Puppet: version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; version 2.7.6 only; version 2.7.8 only; …
- Puppet Puppet Enterprise: up to and including 2.5.1
- Puppetlabs Puppet: up to and including 2.7.17; version 2.7.0 only; version 2.7.1 only
Published 2012-08-06. Last modified 2026-06-16.