Back

MEDIUM

puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions

Published Feb 9, 2018

Description

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having security impact of Low. This issue affects the versions of puppet as shipped with: * Red Hat Satellite 6. A future update may address this issue. * Red Hat OpenStack Platform versions 6-12. Although the affected code is present in shipped packages, the affected code can only be exploited by deploying unsupported custom puppet modules. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner puppet
Published Feb 9, 2018
Updated Sep 17, 2024
Reserved Jun 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 28, 2017
GHSA-VW22-465P-8J5W