Description
dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for files within the archive. dp-puppet version 1.2.7 will recreate installations if the owner or group of any file or directory within that installation does not match the requested owner or group
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24523 | dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for files within the archive. dp-puppet version 1.2.7 will recreate installations if the owner or group of any file or directory within that installation does not match the requested owner or group |
References
History
Fri, 11 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danielparks
Danielparks dp-golang |
|
| CPEs | cpe:2.3:a:danielparks:dp-golang:*:*:*:*:*:puppet:*:* | |
| Vendors & Products |
Danielparks
Danielparks dp-golang |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-08T19:56:17.827Z
Reserved: 2024-02-22T18:08:38.874Z
Link: CVE-2024-27294
Updated: 2024-08-02T00:28:00.333Z
Status : Analyzed
Published: 2024-02-29T23:15:08.250
Modified: 2025-04-11T16:58:53.520
Link: CVE-2024-27294
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD