DescriptionPuppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
Debian Bugs778265

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
facter (PTS)stretch2.4.6-1fixed
bookworm, sid3.14.12-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
factersourcesqueeze(not affected)


[jessie] - facter <no-dsa> (Minor issue)
[squeeze] - facter <not-affected> (Uses version 2008-02-01 of the EC2 API which does not expose security credentials)
[wheezy] - facter <no-dsa> (Minor issue)
The assessment for Squeeze being unaffected is based on the fact that the code accesses and that mentions the iam/security-credentials/role key as being introduced in version 2012-01-12.

Search for package or bug name: Reporting problems