Impact
The vulnerability allows an authenticated Puppet administrator to inject arbitrary shell commands through the java_keystore_passwd parameter. The attacker can supply a value that is rendered directly by the system's shell without proper escaping, resulting in arbitrary command execution. Because the commands run with root privileges, exploitation can compromise the entire system, affecting confidentiality, integrity, and availability. The weakness is a classic input validation flaw that can trigger command injection.
Affected Systems
Perforce Software’s Puppet Enterprise platform is impacted. Versions before the vendor’s release of the fix (exact version numbers not provided) are vulnerable, and any enterprise deployment relying on older releases should verify their installed version.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. The EPSS score is not available, but the lack of a public exploit does not diminish the danger, given the high privilege level required and the devastating outcome of successful exploitation. The vulnerability is not listed in CISA KEV, but it remains a critical risk for organizations that rely on Puppet Enterprise for configuration management and still maintain legacy installations. The attack vector is local: the attacker must be authenticated with administrative privileges, but once achieved, the ability to execute arbitrary commands as root presents a full compromise potential.
OpenCVE Enrichment