CVSS 3 Base Score:
Posted On:
Assessed Risk Level:
A bug in Puppet uses a predictable file name and allows writing to files on the puppet master.
The telnet connection type for managing network devices opens a NET::Telnet connection whose output log is written to a predictable location (/tmp/out.log). That log can be replaced by a symlink to an arbitrary location, potentially overwriting files.Note: This only affects the 2.7 series of Puppet.