Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1oM2doLTk3OHItNzQ3d84AATUz
puppetlabs-rabbitmq allows local users to obtain sensitive information
puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter.
Permalink: https://github.com/advisories/GHSA-h3gh-978r-747wJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM2doLTk3OHItNzQ3d84AATUz
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 2 years ago
Updated: about 2 years ago
Identifiers: GHSA-h3gh-978r-747w, CVE-2014-9568
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-9568
- http://puppetlabs.com/security/cve/cve-2014-9568
- https://github.com/advisories/GHSA-h3gh-978r-747w
Affected Packages
hex:puppetlabs-rabbitmq
Affected Version Ranges: >= 3.0, <= 4.1Fixed in: 5.0