SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2274

Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.

MEDIUM 6.5EPSS 2.91%

Does this matter?

Lower severity and a low EPSS score (2.91%). Track it; it rarely justifies an emergency change on its own.

Description

Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.91% probability · 86th percentile
CISA KEV
Not listed
Affected
puppet/puppet · puppetlabs/puppet · puppet/puppet enterprise
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.