7.1
CVE-2013-1653
- EPSS 5.38%
- Veröffentlicht 20.03.2013 16:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppetlabs ≫ Puppet Version 2.7.0
Puppetlabs ≫ Puppet Version 2.7.1
Puppetlabs ≫ Puppet Version 2.7.19
Puppetlabs ≫ Puppet Version 2.7.20
Puppetlabs ≫ Puppet Version 2.7.20 Update rc1
Puppet ≫ Puppet Enterprise Version 3.1.0
Puppetlabs ≫ Puppet Version 1.0 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.1 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.0 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.1 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.2 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.3 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.4 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.5 SwEdition enterprise
Puppetlabs ≫ Puppet Version 1.2.6 SwEdition enterprise
Puppet ≫ Puppet Enterprise Version 2.7.0
Puppet ≫ Puppet Enterprise Version 2.7.1
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.38% | 0.916 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.1 | 3.9 | 10 |
AV:N/AC:H/Au:S/C:C/I:C/A:C
|
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html
http://secunia.com/advisories/52596
http://ubuntu.com/usn/usn-1759-1
http://www.debian.org/security/2013/dsa-2643
http://www.securityfocus.com/bid/58446
https://puppetlabs.com/security/cve/cve-2013-1653/