5
CVSSv2

CVE-2013-4967

Published: 20/08/2013 Updated: 10/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Puppet Enterprise prior to 3.0.1 allows remote malicious users to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2.8.2

puppet puppet enterprise 2.8.1

puppet puppet enterprise 2.8.0

puppet puppet enterprise 2.5.2

puppet puppet enterprise

puppet puppet enterprise 2.8.3

puppet puppet enterprise 2.5.1