CVE Vulnerabilities

CVE-2018-6516

Published: Jun 14, 2018 | Modified: Oct 03, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.

Affected Software

Name Vendor Start Version End Version
Puppet_enterprise_client_tools Puppet 16.4.0 (including) 16.4.6 (excluding)
Puppet_enterprise_client_tools Puppet 17.3.0 (including) 17.3.6 (excluding)
Puppet_enterprise_client_tools Puppet 18.1.0 (including) 18.1.2 (excluding)

References