{"id":"GHSA-j436-h7hm-rx46","summary":"Puppet Labs Facter allows local users to obtain sensitive Amazon EC2 IAM instance metadata","details":"Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.","aliases":["CVE-2015-1426"],"modified":"2024-12-04T05:29:24.528466Z","published":"2022-05-14T00:56:48Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-06-07T15:07:38Z","nvd_published_at":"2015-02-23T17:59:00Z","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1426"},{"type":"PACKAGE","url":"https://github.com/puppetlabs/facter"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/facter/CVE-2015-1426.yml"},{"type":"WEB","url":"https://web.archive.org/web/20150906195742/http://puppetlabs.com/security/cve/cve-2015-1426"},{"type":"WEB","url":"https://www.puppet.com/security/cve/cve-2015-1426-potential-sensitive-information-leakage-facters-amazon-ec2-metadata"}],"affected":[{"package":{"name":"facter","ecosystem":"RubyGems","purl":"pkg:gem/facter"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.0"},{"fixed":"2.4.1"}]}],"versions":["1.6.0","1.6.1","1.6.10","1.6.11","1.6.12","1.6.12.rc1","1.6.12.rc2","1.6.13","1.6.13.rc1","1.6.14","1.6.14.rc1","1.6.15","1.6.15.rc1","1.6.16","1.6.17","1.6.17.rc1","1.6.18","1.6.18.rc1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.0.rc1","1.7.0.rc2","1.7.1","1.7.1.rc1","1.7.2","1.7.2.rc1","1.7.3","1.7.3.rc1","1.7.4","1.7.4.rc1","1.7.5","1.7.5.rc1","1.7.5.rc2","1.7.6","2.0.1","2.0.1.rc1","2.0.1.rc2","2.0.1.rc3","2.0.1.rc4","2.0.2","2.1.0","2.2.0","2.3.0","2.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j436-h7hm-rx46/GHSA-j436-h7hm-rx46.json"}}],"schema_version":"1.9.0"}