CVE-2012-3865 is a directory traversal vulnerability affecting Puppet versions prior to 2.6.17 and 2.7.18, and Puppet Enterprise before 2.5.2. When Delete is enabled in auth.conf, authenticated remote attackers can delete arbitrary files on the Puppet master server by manipulating node names with dot-dot sequences. This vulnerability has a CVSS score of 3.5, indicating a medium attack complexity and partial impact on availability, but no impact on confidentiality or integrity. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7.2CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:* | ||
2.7.3CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.3:*:*:*:*:*:*:* | ||
2.7.4CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.4:*:*:*:*:*:*:* | ||
2.7.5CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.5:*:*:*:*:*:*:* | ||
2.7.6CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.