{"id":"CVE-2011-0528","aliases":["GHSA-9pvx-fwwh-w289"],"url":"https://o3.security/vulnerability/CVE-2011-0528","summary":"Puppet does not properly restrict access to node resources","details":"Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.","published":"2014-02-17T16:55:04Z","modified":"2026-04-10T03:41:37.634134Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"puppet","fixedVersion":"2.6.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1365-1"},{"type":"WEB","url":"http://www.mail-archive.com/puppet-users%40googlegroups.com/msg16429.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/01/27/6"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/01/31/5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:41:37.634134Z"}}