7.5
CVE-2013-3567
- EPSS 3.41%
- Veröffentlicht 19.08.2013 23:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppetlabs ≫ Puppet Version 2.7.0
Puppetlabs ≫ Puppet Version 2.7.1
Puppetlabs ≫ Puppet Version 2.7.19
Puppetlabs ≫ Puppet Version 2.7.20
Puppetlabs ≫ Puppet Version 2.7.20 Update rc1
Puppetlabs ≫ Puppet Version 3.2.0
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Novell ≫ Suse Linux Enterprise Desktop Version 11 Update sp3
Novell ≫ Suse Linux Enterprise Desktop Version 11.0 Update sp2
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp2 SwPlatform vmware
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp3
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp3 SwPlatform vmware
Puppet ≫ Puppet Enterprise Version <= 2.8.1
Puppet ≫ Puppet Enterprise Version 1.0
Puppet ≫ Puppet Enterprise Version 1.1
Puppet ≫ Puppet Enterprise Version 1.2.0
Puppet ≫ Puppet Enterprise Version 2.0.0
Puppet ≫ Puppet Enterprise Version 2.5.1
Puppet ≫ Puppet Enterprise Version 2.5.2
Puppet ≫ Puppet Enterprise Version 2.8.0
Puppetlabs ≫ Puppet Version 1.0.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 1.1.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 1.2.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 2.5.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 2.6.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 2.7.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 2.7.1 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 2.7.2 Update - Edition enterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.41% | 0.873 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00019.html
http://rhn.redhat.com/errata/RHSA-2013-1283.html
http://rhn.redhat.com/errata/RHSA-2013-1284.html
http://secunia.com/advisories/54429
http://www.debian.org/security/2013/dsa-2715
http://www.ubuntu.com/usn/USN-1886-1
https://puppetlabs.com/security/cve/cve-2013-3567/