8.5

CVE-2013-1398

The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.

Data is provided by the National Vulnerability Database (NVD)
PuppetPuppet Enterprise Version <= 2.7.0
PuppetPuppet Enterprise Version2.0.0
PuppetPuppet Enterprise Version2.5.1
PuppetPuppet Enterprise Version2.5.2
PuppetlabsPuppet Version2.5.0 Update- Editionenterprise
PuppetlabsPuppet Version2.6.0 Update- Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.62% 0.674
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C