Low severityNVD Advisory· Published Aug 6, 2012· Updated Apr 29, 2026
CVE-2012-3866
CVE-2012-3866
Description
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
puppetRubyGems | >= 2.7.0, < 2.7.18 | 2.7.18 |
Affected products
17cpe:2.3:a:puppetlabs:puppet:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:puppetlabs:puppet:*:*:*:*:*:*:*:*range: <=2.7.17
- cpe:2.3:a:puppetlabs:puppet:2.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:puppetlabs:puppet:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.11:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.12:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.13:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.14:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.16:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet:2.7.9:*:*:*:*:*:*:*
Patches
1fd44bf5e6d0dVulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
12- github.com/puppetlabs/puppet/commit/fd44bf5e6d0d360f6a493d663b653c121fa83c3fnvdExploitPatchWEB
- puppetlabs.com/security/cve/cve-2012-3866/nvdVendor Advisory
- github.com/advisories/GHSA-8jxj-9r5f-w3m2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2012-3866ghsaADVISORY
- lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlnvdWEB
- puppetlabs.com/security/cve/cve-2012-3866ghsaWEB
- www.debian.org/security/2012/dsa-2511nvdWEB
- www.ubuntu.com/usn/USN-1506-1nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2012-3866.ymlghsaWEB
- www.puppet.com/security/cve/cve-2012-3866-lastrunreportyaml-world-readableghsaWEB
- secunia.com/advisories/50014nvd
News mentions
0No linked articles in our index yet.