Puppet contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the program stores last run reports with world readable permissions, which will disclose potentially sensitive system information to a local attacker.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Authentication Required
Solution
Upgrade to Puppet to version 2.6.17 or 2.7.18 or higher and Puppet Enterprise to version 2.5.2 or higher, as they have been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.