6.8
CVSSv2

CVE-2013-4957

Published: 25/10/2013 Updated: 10/07/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The dashboard report in Puppet Enterprise prior to 3.0.1 allows malicious users to execute arbitrary YAML code via a crafted report-specific type.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise

puppet puppet enterprise 2.8.3

puppet puppet enterprise 2.8.0

puppet puppet enterprise 2.5.2

puppet puppet enterprise 2.8.2

puppet puppet enterprise 2.8.1

puppet puppet enterprise 2.5.1