Loading HuntDB...

GHSA-vw22-465p-8j5w

GitHub Security Advisory

Tarball permission preservation in puppet

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

When installing a module using the system tar, the PMT will filter filesystem permissions to a sane value. This may just be based on the user's umask.

When using minitar, files are unpacked with whatever permissions are in the tarball. This is potentially unsafe, as tarballs can be easily created with weird permissions.

Affected Packages

RubyGems puppet
Affected versions: 0 (fixed in 4.10.10)
RubyGems puppet
Affected versions: 5.0.0 (fixed in 5.3.4)

Related CVEs

Key Information

GHSA ID
GHSA-vw22-465p-8j5w
Published
May 13, 2022 1:41 AM
Last Modified
July 21, 2022 10:29 PM
CVSS Score
5.0 /10
Primary Ecosystem
RubyGems
Primary Package
puppet
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 11, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.