Puppet contains a flaw that may allow a malicious local user to access arbitrary files on the system. The issue is due to the programming creating temporary files insecurely when handling filebucket REST requests.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Upgrade to version 2.6.15 or 2.7.13 or 2.5.1 for Enterprise or higher, as they have been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.