AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-1986

LOW · CVSS 2.1 EPSS 1.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-05-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2012-1986
Severity
LOW
CVSS
2.1
EPSS
1.47%

Original NVD Description

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.