In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://usn.ubuntu.com/3567-1/ | third party advisory vendor advisory |
https://puppet.com/security/cve/CVE-2017-10689 | vendor advisory |
https://access.redhat.com/errata/RHSA-2018:2927 | third party advisory vendor advisory |