CVE-2011-3870

EPSS 0.03%

Puppet allows local users to modify the permissions of arbitrary files

發布日:2022/5/14修改日:2026/4/28

描述

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.

受影響套件(2)

參考連結(14)