GHSA-j436-h7hm-rx46

Suggest an improvement
Source
https://github.com/advisories/GHSA-j436-h7hm-rx46
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j436-h7hm-rx46/GHSA-j436-h7hm-rx46.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j436-h7hm-rx46
Aliases
Published
2022-05-14T00:56:48Z
Modified
2024-12-04T05:29:24.528466Z
Summary
Puppet Labs Facter allows local users to obtain sensitive Amazon EC2 IAM instance metadata
Details

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

Database specific
{
    "nvd_published_at": "2015-02-23T17:59:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2023-06-07T15:07:38Z"
}
References

Affected packages

RubyGems / facter

Package

Name
facter
Purl
pkg:gem/facter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.0
Fixed
2.4.1

Affected versions

1.*

1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.6.10
1.6.11
1.6.12.rc1
1.6.12.rc2
1.6.12
1.6.13.rc1
1.6.13
1.6.14.rc1
1.6.14
1.6.15.rc1
1.6.15
1.6.16
1.6.17.rc1
1.6.17
1.6.18.rc1
1.6.18
1.7.0.rc1
1.7.0.rc2
1.7.0
1.7.1.rc1
1.7.1
1.7.2.rc1
1.7.2
1.7.3.rc1
1.7.3
1.7.4.rc1
1.7.4
1.7.5.rc1
1.7.5.rc2
1.7.5
1.7.6

2.*

2.0.1.rc1
2.0.1.rc2
2.0.1.rc3
2.0.1.rc4
2.0.1
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0