8
CVSSv3

CVE-2018-6508

Published: 09/02/2018 Updated: 24/01/2022
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Puppet Enterprise 2017.3.x before 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise

Vendor Advisories

Puppet Enterprise 20173x prior to 201733 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability ...