 
                        We found results for “”
CVE-2012-1053
Good to know:
 
                                    Date: May 29, 2012
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups. Converted from WS-2017-0165, on 2022-11-08.
Language: Ruby
Severity Score
Related Resources (27)
Severity Score
Weakness Type (CWE)
Top Fix
 
                                    CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | LOCAL | 
| Attack Complexity (AC): | HIGH | 
| Privileges Required (PR): | NONE | 
| User Interaction (UI): | NONE | 
| Scope (S): | UNCHANGED | 
| Confidentiality (C): | HIGH | 
| Integrity (I): | HIGH | 
| Availability (A): | HIGH | 
CVSS v2
| Base Score: |  | 
|---|---|
| Access Vector (AV): | LOCAL | 
| Access Complexity (AC): | MEDIUM | 
| Authentication (AU): | NONE | 
| Confidentiality (C): | COMPLETE | 
| Integrity (I): | COMPLETE | 
| Availability (A): | COMPLETE | 
| Additional information: | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

