CVE-2014-7170

Puppet Server <0.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://puppetlabs.com/security/cve/cve-2014-7170

Scores

EPSS 0.0023
EPSS Percentile 13.3%

Details

CWE
CWE-362
Status published
Products (1)
puppet/puppet_server 0.2.0
Published Dec 17, 2014
Tracked Since Feb 18, 2026