9
CVE-2013-1640
- EPSS 4.93%
- Veröffentlicht 20.03.2013 16:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppet ≫ Puppet Enterprise Version < 1.2.7
Puppet ≫ Puppet Enterprise Version 2.7.0
Puppet ≫ Puppet Enterprise Version 2.7.1
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.93% | 0.91 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html
http://rhn.redhat.com/errata/RHSA-2013-0710.html
http://secunia.com/advisories/52596
http://ubuntu.com/usn/usn-1759-1
http://www.debian.org/security/2013/dsa-2643
https://puppetlabs.com/security/cve/cve-2013-1640/