Back

LOW

facter: potential sensitive information leakage in Facter's Amazon EC2 metadata facts handling

Published Feb 23, 2015

Description

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of facter as shipped with various Red Hat products as they do not use puppet and facter to control Amazon EC2 instances directly.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 23, 2015
Updated Aug 6, 2024
Reserved Jan 30, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 10, 2015
GHSA-J436-H7HM-RX46