{"id":"GHSA-9pvx-fwwh-w289","summary":"Puppet does not properly restrict access to node resources","details":"Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.","aliases":["CVE-2011-0528"],"modified":"2024-12-02T05:37:56.401336Z","published":"2022-05-14T00:56:55Z","database_specific":{"github_reviewed_at":"2024-01-16T21:20:45Z","nvd_published_at":"2014-02-17T16:55:00Z","cwe_ids":["CWE-284"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0528"},{"type":"WEB","url":"https://github.com/puppetlabs/puppet/commit/eee1a9cdaa5cab6222c8e6ab087d319f976fa4e3"},{"type":"PACKAGE","url":"https://github.com/puppetlabs/puppet"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2011-0528.yml"},{"type":"WEB","url":"http://www.mail-archive.com/puppet-users@googlegroups.com/msg16429.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/01/27/6"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/01/31/5"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-1365-1"}],"affected":[{"package":{"name":"puppet","ecosystem":"RubyGems","purl":"pkg:gem/puppet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.4"}]}],"versions":["2.6.0","2.6.1","2.6.2","2.6.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.6.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9pvx-fwwh-w289/GHSA-9pvx-fwwh-w289.json"}}],"schema_version":"1.9.0"}