7.5

CVE-2013-1655

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."

Data is provided by the National Vulnerability Database (NVD)
PuppetPuppet Version2.7.2
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.3
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.4
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.5
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.6
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.7
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.8
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.9
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.10
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.11
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.12
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.13
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.14
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.16
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.17
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Version2.7.18
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetPuppet Enterprise Version3.1.0
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetlabsPuppet Version2.7.0
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetlabsPuppet Version2.7.1
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetlabsPuppet Version2.7.19
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetlabsPuppet Version2.7.20
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
PuppetlabsPuppet Version2.7.20 Updaterc1
   Ruby-langRuby Version1.9
   Ruby-langRuby Version1.9.1
   Ruby-langRuby Version1.9.2
   Ruby-langRuby Version1.9.3
   Ruby-langRuby Version1.9.3 Updatep0
   Ruby-langRuby Version1.9.3 Updatep125
   Ruby-langRuby Version1.9.3 Updatep194
   Ruby-langRuby Version1.9.3 Updatep286
   Ruby-langRuby Version1.9.3 Updatep383
   Ruby-langRuby Version2.0
   Ruby-langRuby Version2.0.0
   Ruby-langRuby Version2.0.0 Updaterc1
   Ruby-langRuby Version2.0.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.75% 0.725
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.