4
CVSSv2

CVE-2013-2275

Published: 20/03/2013 Updated: 10/07/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The default configuration for puppet masters 0.25.0 and later in Puppet prior to 2.6.18, 2.7.x prior to 2.7.21, and 3.1.x prior to 3.1.1, and Puppet Enterprise prior to 1.2.7 and 2.7.x prior to 2.7.2, allows remote authenticated nodes to submit reports for other nodes via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet 2.6.0

puppet puppet 2.6.15

puppet puppet 2.6.16

puppet puppet 2.6.14

puppet puppet 2.6.4

puppet puppet 2.6.3

puppet puppet 2.6.2

puppet puppet 2.6.1

puppetlabs puppet

puppet puppet 2.6.12

puppet puppet 2.6.9

puppet puppet 2.6.10

puppet puppet 2.6.8

puppet puppet 2.6.6

puppet puppet 2.6.13

puppet puppet 2.6.11

puppet puppet 2.6.7

puppet puppet 2.6.5

puppetlabs puppet 2.7.19

puppetlabs puppet 2.7.20

puppet puppet 2.7.9

puppet puppet 2.7.4

puppet puppet 2.7.3

puppet puppet 2.7.12

puppet puppet 2.7.13

puppet puppet 2.7.16

puppet puppet 2.7.14

puppet puppet 2.7.2

puppetlabs puppet 2.7.1

puppet puppet 2.7.11

puppet puppet 2.7.17

puppet puppet 2.7.7

puppet puppet 2.7.8

puppet puppet 2.7.10

puppet puppet 2.7.6

puppet puppet 2.7.18

puppetlabs puppet 2.7.0

puppet puppet 2.7.5

puppet puppet enterprise 3.1.0

puppet puppet enterprise 2.7.0

puppet puppet enterprise 2.7.1

canonical ubuntu linux 12.10

canonical ubuntu linux 11.10

canonical ubuntu linux 12.04

Vendor Advisories

Synopsis Important: puppet security update Type/Severity Security Advisory: Important Topic Updated puppet packages that fix several security issues are now availablefor Red Hat OpenStack FolsomThe Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerability ...
Several security issues were fixed in Puppet ...
Multiple vulnerabilities were discovered in Puppet, a centralized configuration management system CVE-2013-1640 An authenticated malicious client may request its catalog from the puppet master, and cause the puppet master to execute arbitrary code The puppet master must be made to invoke the template or inline_template functions ...