CVE-2012-3866: Puppet

Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.

lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

Affected products

  • Puppet Puppet: version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; version 2.7.6 only; version 2.7.8 only; …
  • Puppet Puppet Enterprise: up to and including 2.5.1
  • Puppetlabs Puppet: up to and including 2.7.17; version 2.7.0 only; version 2.7.1 only

Published 2012-08-06. Last modified 2026-06-16.