VulnerabilityModified
CVE-2013-2274
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.
MEDIUM 6.5EPSS 2.91%
Does this matter?
Lower severity and a low EPSS score (2.91%). Track it; it rarely justifies an emergency change on its own.
Description
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.91% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- puppet/puppet · puppetlabs/puppet · puppet/puppet enterprise
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html
- http://rhn.redhat.com/errata/RHSA-2013-0710.html
- http://secunia.com/advisories/52596Vendor Advisory
- http://www.debian.org/security/2013/dsa-2643
- http://www.securityfocus.com/bid/58447
- https://puppetlabs.com/security/cve/cve-2013-2274/Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html
- http://rhn.redhat.com/errata/RHSA-2013-0710.html
- http://secunia.com/advisories/52596Vendor Advisory
- http://www.debian.org/security/2013/dsa-2643
- http://www.securityfocus.com/bid/58447
- https://puppetlabs.com/security/cve/cve-2013-2274/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.