CVE-2017-2290
Beschrijving NL
Op Windows-installaties van de mcollective-puppet-agent-plug-in, versie 1.12.0, kan een niet-beheerder een uitvoerbaar bestand maken dat wordt uitgevoerd met beheerdersbevoegdheden bij de volgende "mco puppet" -run. Puppet Enterprise-gebruikers worden niet beïnvloed. Dit wordt opgelost in mcollective-puppet-agent 1.12.1.
Origineel (Engels) tonen
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.