CVE Vulnerabilities

CVE-2013-1640

Published: Mar 20, 2013 | Modified: Jan 24, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH

The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.

Affected Software

Name Vendor Start Version End Version
Puppet Puppet * 2.6.18 (excluding)
OpenStack Folsom for RHEL 6 RedHat puppet-0:2.6.18-1.el6ost *
Puppet Ubuntu devel *
Puppet Ubuntu hardy *
Puppet Ubuntu lucid *
Puppet Ubuntu oneiric *
Puppet Ubuntu precise *
Puppet Ubuntu quantal *
Puppet Ubuntu upstream *

References