CVE-2009-3564
Published Oct 6, 2009puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Vendor archive
1 CVEs tagged to vendor reductivelabs — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.