CVE-2017-10689

MEDIUM

Puppet < 5.3.4 and Puppet Enterprise < 2016.4.10 - Improper Privilege Management

Title source: llm
STIX 2.1

Description

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

References (3)

Core 3
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3567-1/
Vendor Advisory x_refsource_confirm
https://puppet.com/security/cve/CVE-2017-10689
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2927

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 25.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-269
Status published
Products (5)
canonical/ubuntu_linux 14.04
puppet/puppet < 5.3.4
puppet/puppet_enterprise < 2016.4.10
redhat/satellite 6.4
rubygems/puppet 0 - 4.10.10RubyGems
Published Feb 09, 2018
Tracked Since Feb 18, 2026