CVE Vulnerabilities

CVE-2013-1640

Published: Mar 20, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet*2.6.18 (excluding)
OpenStack Folsom for RHEL 6RedHatpuppet-0:2.6.18-1.el6ost*
PuppetUbuntudevel*
PuppetUbuntuhardy*
PuppetUbuntulucid*
PuppetUbuntuoneiric*
PuppetUbuntuprecise*
PuppetUbuntuquantal*
PuppetUbuntuupstream*

References