7.5
CVSSv2

CVE-2013-1655

Published: 20/03/2013 Updated: 10/07/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Puppet 2.7.x prior to 2.7.21 and 3.1.x prior to 3.1.1, when running Ruby 1.9.3 or later, allows remote malicious users to execute arbitrary code via vectors related to "serialized attributes."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppetlabs puppet 2.7.20

puppetlabs puppet 2.7.1

puppetlabs puppet 2.7.0

puppet puppet 2.7.16

puppet puppet 2.7.3

puppet puppet 2.7.11

puppet puppet 2.7.2

puppet puppet 2.7.13

puppet puppet 2.7.8

puppet puppet 2.7.10

puppet puppet_enterprise 3.1.0

puppet puppet 2.7.18

puppet puppet 2.7.17

puppet puppet 2.7.9

puppet puppet 2.7.4

puppetlabs puppet 2.7.19

puppet puppet 2.7.6

puppet puppet 2.7.7

puppet puppet 2.7.5

puppet puppet 2.7.14

puppet puppet 2.7.12

Vendor Advisories

Several security issues were fixed in Puppet ...
Multiple vulnerabilities were discovered in Puppet, a centralized configuration management system CVE-2013-1640 An authenticated malicious client may request its catalog from the puppet master, and cause the puppet master to execute arbitrary code The puppet master must be made to invoke the template or inline_template functions ...