7.1

CVE-2013-1653

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PuppetPuppet Version >= 2.6.0 <= 2.6.17
PuppetPuppet Version2.7.2
PuppetPuppet Version2.7.3
PuppetPuppet Version2.7.4
PuppetPuppet Version2.7.5
PuppetPuppet Version2.7.6
PuppetPuppet Version2.7.7
PuppetPuppet Version2.7.8
PuppetPuppet Version2.7.9
PuppetPuppet Version2.7.10
PuppetPuppet Version2.7.11
PuppetPuppet Version2.7.12
PuppetPuppet Version2.7.13
PuppetPuppet Version2.7.14
PuppetPuppet Version2.7.16
PuppetPuppet Version2.7.17
PuppetPuppet Version2.7.18
PuppetlabsPuppet Version2.7.0
PuppetlabsPuppet Version2.7.1
PuppetlabsPuppet Version2.7.19
PuppetlabsPuppet Version2.7.20
PuppetlabsPuppet Version2.7.20 Updaterc1
PuppetPuppet Enterprise Version3.1.0
PuppetlabsPuppet Version1.0 SwEditionenterprise
PuppetlabsPuppet Version1.1 SwEditionenterprise
PuppetlabsPuppet Version1.2.0 SwEditionenterprise
PuppetlabsPuppet Version1.2.1 SwEditionenterprise
PuppetlabsPuppet Version1.2.2 SwEditionenterprise
PuppetlabsPuppet Version1.2.3 SwEditionenterprise
PuppetlabsPuppet Version1.2.4 SwEditionenterprise
PuppetlabsPuppet Version1.2.5 SwEditionenterprise
PuppetlabsPuppet Version1.2.6 SwEditionenterprise
PuppetPuppet Enterprise Version2.7.0
PuppetPuppet Enterprise Version2.7.1
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.55% 0.806
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 3.9 10
AV:N/AC:H/Au:S/C:C/I:C/A:C