CVE Vulnerabilities

CVE-2013-2274

Published: Mar 20, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet2.6.0 (including)2.6.0 (including)
PuppetPuppet2.6.1 (including)2.6.1 (including)
PuppetPuppet2.6.2 (including)2.6.2 (including)
PuppetPuppet2.6.3 (including)2.6.3 (including)
PuppetPuppet2.6.4 (including)2.6.4 (including)
PuppetPuppet2.6.5 (including)2.6.5 (including)
PuppetPuppet2.6.6 (including)2.6.6 (including)
PuppetPuppet2.6.7 (including)2.6.7 (including)
PuppetPuppet2.6.8 (including)2.6.8 (including)
PuppetPuppet2.6.9 (including)2.6.9 (including)
PuppetPuppet2.6.10 (including)2.6.10 (including)
PuppetPuppet2.6.11 (including)2.6.11 (including)
PuppetPuppet2.6.12 (including)2.6.12 (including)
PuppetPuppet2.6.13 (including)2.6.13 (including)
PuppetPuppet2.6.14 (including)2.6.14 (including)
PuppetPuppet2.6.15 (including)2.6.15 (including)
PuppetPuppet2.6.16 (including)2.6.16 (including)
PuppetPuppetlabs2.6.17 (including)2.6.17 (including)
OpenStack Folsom for RHEL 6RedHatpuppet-0:2.6.18-1.el6ost*
PuppetUbuntuhardy*
PuppetUbuntuupstream*

References