Vulnerability Description
Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Puppet | Facter | 1.6.0 |
| Puppetlabs | Facter | 1.6.1 |
Related Weaknesses (CWE)
References
- http://puppetlabs.com/security/cve/cve-2015-1426Vendor Advisory
- http://puppetlabs.com/security/cve/cve-2015-1426Vendor Advisory
FAQ
What is CVE-2015-1426?
CVE-2015-1426 is a vulnerability with a CVSS score of 2.1 (LOW). Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.
How severe is CVE-2015-1426?
CVE-2015-1426 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1426?
Check the references section above for vendor advisories and patch information. Affected products include: Puppet Facter, Puppetlabs Facter.