Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
| Software | From | Fixed in |
|---|---|---|
| puppetlabs / puppet | 2.7.0 | 2.7.0.x |
| puppetlabs / puppet | 2.7.1 | 2.7.1.x |
| puppet / puppet | 2.6.0 | 2.6.0.x |
| puppet / puppet | 2.6.1 | 2.6.1.x |
| puppet / puppet | 2.6.2 | 2.6.2.x |
| puppet / puppet | 2.6.3 | 2.6.3.x |
| puppet / puppet | 2.6.4 | 2.6.4.x |
| puppet / puppet | 2.6.5 | 2.6.5.x |
| puppet / puppet | 2.6.6 | 2.6.6.x |
| puppet / puppet | 2.6.7 | 2.6.7.x |
| puppet / puppet | 2.6.8 | 2.6.8.x |
| puppet / puppet | 2.6.9 | 2.6.9.x |
| puppet / puppet | 2.7.2 | 2.7.2.x |
| puppet / puppet | 2.7.3 | 2.7.3.x |