Executive brief
puppet-facter is a Node.js library that retrieves system fact data by executing the facter system utility. The getFact function fails to properly sanitize user-supplied input before passing it to shell commands, allowing an attacker to inject arbitrary shell commands and execute them with the privileges of the application.
Technical details
The vulnerability is a command injection flaw (CWE-77, CWE-78) in the getFact function. The root cause is improper input sanitization of the factName parameter, which is directly concatenated into a shell command string passed to child_process.exec(). An attacker who can control the factName argument can inject shell metacharacters and arbitrary commands. The attack requires local or authenticated access to the application that uses puppet-facter. Successful exploitation allows arbitrary command execution with the privileges of the Node.js process. All versions up to and including 0.0.2 are affected; no patch availability is indicated in the advisory.
Affected products
- npm puppet-facter 0.0.2 and earlier
Timeline
- 2023-01-26: disclosed
- 2023-01-27: advisory: GitHub security advisory reviewed