8.5
CVSSv2

CVE-2013-1398

Published: 14/03/2014 Updated: 10/07/2019
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

The pe_mcollective module in Puppet Enterprise (PE) prior to 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2.5.1

puppetlabs puppet 2.5.0

puppet puppet enterprise 2.0.0

puppet puppet enterprise

puppet puppet enterprise 2.5.2

puppetlabs puppet 2.6.0