CVE Vulnerabilities

CVE-2013-1652

Published: Mar 20, 2013 | Modified: Jul 10, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the masters cache via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Puppet Puppetlabs * 2.6.17 (including)
OpenStack Folsom for RHEL 6 RedHat puppet-0:2.6.18-1.el6ost *
Puppet Ubuntu devel *
Puppet Ubuntu hardy *
Puppet Ubuntu lucid *
Puppet Ubuntu oneiric *
Puppet Ubuntu precise *
Puppet Ubuntu quantal *
Puppet Ubuntu upstream *

References