CVE-2014-3248: Puppet Facter
Medium severity, CVSS 6.2. EPSS: 0.5% chance of exploitation in the next 30 days.
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine.
Affected products
- Puppet Facter: version 2.0.0 only; version 2.0.1 only
- Puppet Hiera: before 1.3.4 (fixed in 1.3.4)
- Puppet Marionette Collective: before 2.5.2 (fixed in 2.5.2)
- Puppet Puppet: before 2.7.26 (fixed in 2.7.26); from 3.6.0, before 3.6.2 (fixed in 3.6.2)
- Puppet Puppet Enterprise: from 2.8.0, before 2.8.7 (fixed in 2.8.7)
- Puppetlabs Facter: from 1.6.0, up to and including 1.6.18
Published 2014-11-16. Last modified 2026-06-17.