Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.
References
Link Resource
http://puppetlabs.com/security/cve/cve-2015-1426 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2015-02-23T17:00:00

Updated: 2015-02-23T16:57:00

Reserved: 2015-01-30T00:00:00


Link: CVE-2015-1426

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-02-23T17:59:01.680

Modified: 2019-07-11T13:00:07.330


Link: CVE-2015-1426

JSON object: View

cve-icon Redhat Information

No data.

CWE