The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem".
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: puppet
Published: 2017-06-30T20:00:00Z
Updated: 2024-09-16T18:08:33.665Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2298
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-06-30T20:29:00.217
Modified: 2024-11-21T03:23:14.110
Link: CVE-2017-2298
Redhat
No data.