The Puppet Labs Issue Tracker has Moved: https://tickets.puppetlabs.com
file bucket request can execute arbitrary commands as puppet master
|Assignee:||Andrew Parker||% Done:|
|Affected Puppet version:||2.6.0||Branch:|
Ticket tracking is now hosted in JIRA: https://tickets.puppetlabs.com
This issue is currently not available for export. If you are experiencing the issue described below, please file a new ticket in JIRA. Once a new ticket has been created, please add a link to it that points back to this Redmine ticket.
This requires access to the cert on the agent and an unprivileged account on the master.
By creating a path on the master in a world-writable location that matches a command string, one can then make a file bucket request to execute that command.
#2 Updated by Andrew Parker over 2 years ago
- Status changed from Accepted to In Topic Branch Pending Review
Fixes in branches: