Vulnerability identifier: #VU41547
Vulnerability risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2014-3249
CWE-ID:
CWE-200
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Puppet Enterprise
Client/Desktop applications /
Software for system administration
Vendor: Puppet Labs
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Puppet Enterprise: 2.8.0 - 2.8.6
External links
https://puppetlabs.com/security/cve/cve-2014-3249
https://secunia.com/advisories/59197
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.