Search/CVE-2014-7170
CVE

CVE-2014-7170

Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVSS v3.1
EPSS
0.23%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
2 relationships
Timeline
disclosure → media coverage
Dec 17, 2014
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026