7.5
CVE-2013-3567
- EPSS 11.14%
- Published 19.08.2013 23:55:08
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Data is provided by the National Vulnerability Database (NVD)
Puppetlabs ≫ Puppet Version2.7.0
Puppetlabs ≫ Puppet Version2.7.1
Puppetlabs ≫ Puppet Version2.7.19
Puppetlabs ≫ Puppet Version2.7.20
Puppetlabs ≫ Puppet Version2.7.20 Updaterc1
Puppetlabs ≫ Puppet Version3.2.0
Canonical ≫ Ubuntu Linux Version12.04 Update- Editionlts
Canonical ≫ Ubuntu Linux Version12.10
Canonical ≫ Ubuntu Linux Version13.04
Novell ≫ Suse Linux Enterprise Desktop Version11 Updatesp3
Novell ≫ Suse Linux Enterprise Desktop Version11.0 Updatesp2
Novell ≫ Suse Linux Enterprise Server Version11.0 Updatesp2 SwPlatformvmware
Novell ≫ Suse Linux Enterprise Server Version11.0 Updatesp3
Novell ≫ Suse Linux Enterprise Server Version11.0 Updatesp3 SwPlatformvmware
Puppet ≫ Puppet Enterprise Version <= 2.8.1
Puppet ≫ Puppet Enterprise Version1.0
Puppet ≫ Puppet Enterprise Version1.1
Puppet ≫ Puppet Enterprise Version1.2.0
Puppet ≫ Puppet Enterprise Version2.0.0
Puppet ≫ Puppet Enterprise Version2.5.1
Puppet ≫ Puppet Enterprise Version2.5.2
Puppet ≫ Puppet Enterprise Version2.8.0
Puppetlabs ≫ Puppet Version1.0.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version1.1.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version1.2.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version2.5.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version2.6.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version2.7.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version2.7.1 Update- Editionenterprise
Puppetlabs ≫ Puppet Version2.7.2 Update- Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 11.14% | 0.932 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.