|
Puppet contains a flaw related to the parsing of file bucket requests. The Puppet::FileBucket::File object does not sanitize user-supplied input allowing for files to be written to arbitrary locations, or writing to a world-writable location that matches a command string leading to command execution.
|