RubySec

Providing security resources for the Ruby community

CVE-2015-1426 (facter): Puppet Labs Facter allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

ADVISORIES

GEM

facter

SEVERITY

CVSS v3.x: 1.3 (Low)

CVSS v2.0: 2.1 (Low)

UNAFFECTED VERSIONS

  • < 1.6.0

PATCHED VERSIONS

  • >= 2.4.1

DESCRIPTION

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

RELATED