CVE-2013-4761
Published Aug 20, 2013
Last updated 5 years ago
Overview
- Description
- Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:puppet:puppet:3.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "867A327E-421F-46A9-877C-8A2911971E39" }, { "criteria": "cpe:2.3:a:puppet:puppet:3.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75BA8116-F64D-4CB2-A4DE-B21864962029" }, { "criteria": "cpe:2.3:a:puppet:puppet:3.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4F1986C-D984-4B90-A790-5D247902AB8F" }, { "criteria": "cpe:2.3:a:puppetlabs:puppet:3.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12419C96-61A4-46B3-B8DA-FE3B8E7ACAEF" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE56BA6B-BDC4-431E-81FD-D7ED5E8783E9" }, { "criteria": "cpe:2.3:a:puppetlabs:puppet:2.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E5192CB-094F-469E-A644-2255C4F44804" }, { "criteria": "cpe:2.3:a:puppetlabs:puppet:2.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D17D2752-CB0D-4CC8-8604-FEBF8DEE16E0" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:puppet:puppet_enterprise:2.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C43CD3C-ACDB-418B-B67D-9C8EFAC0680C" }, { "criteria": "cpe:2.3:a:puppet:puppet_enterprise:2.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD8F80AD-1E8E-40BE-883D-6F7F61D4A274" }, { "criteria": "cpe:2.3:a:puppet:puppet_enterprise:2.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C6E27BB-6444-49E2-8B89-D7E09284D29C" }, { "criteria": "cpe:2.3:a:puppet:puppet_enterprise:3.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE0A2F50-A73B-4598-BE73-1DDA1084352A" } ], "operator": "OR" } ] } ]