telnet.rb
in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log
).
{ "nvd_published_at": "2012-06-27T18:55:01Z", "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:30:16Z" }