7.5

CVE-2013-3567

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.

Data is provided by the National Vulnerability Database (NVD)
PuppetPuppet Version2.7.2
PuppetPuppet Version2.7.10
PuppetPuppet Version2.7.11
PuppetPuppet Version2.7.12
PuppetPuppet Version2.7.13
PuppetPuppet Version2.7.14
PuppetPuppet Version2.7.16
PuppetPuppet Version2.7.17
PuppetPuppet Version2.7.18
PuppetPuppet Version2.7.21
PuppetPuppet Version3.2.1
PuppetlabsPuppet Version2.7.0
PuppetlabsPuppet Version2.7.1
PuppetlabsPuppet Version2.7.19
PuppetlabsPuppet Version2.7.20
PuppetlabsPuppet Version2.7.20 Updaterc1
PuppetlabsPuppet Version3.2.0
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
CanonicalUbuntu Linux Version13.04
NovellSuse Linux Enterprise Desktop Version11 Updatesp3
NovellSuse Linux Enterprise Desktop Version11.0 Updatesp2
NovellSuse Linux Enterprise Server Version11.0 Updatesp2 SwPlatformvmware
NovellSuse Linux Enterprise Server Version11.0 Updatesp3
NovellSuse Linux Enterprise Server Version11.0 Updatesp3 SwPlatformvmware
PuppetPuppet Enterprise Version <= 2.8.1
PuppetPuppet Enterprise Version1.0
PuppetPuppet Enterprise Version1.1
PuppetPuppet Enterprise Version1.2.0
PuppetPuppet Enterprise Version2.0.0
PuppetPuppet Enterprise Version2.5.1
PuppetPuppet Enterprise Version2.5.2
PuppetPuppet Enterprise Version2.8.0
PuppetlabsPuppet Version1.0.0 Update- Editionenterprise
PuppetlabsPuppet Version1.1.0 Update- Editionenterprise
PuppetlabsPuppet Version1.2.0 Update- Editionenterprise
PuppetlabsPuppet Version2.5.0 Update- Editionenterprise
PuppetlabsPuppet Version2.6.0 Update- Editionenterprise
PuppetlabsPuppet Version2.7.0 Update- Editionenterprise
PuppetlabsPuppet Version2.7.1 Update- Editionenterprise
PuppetlabsPuppet Version2.7.2 Update- Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 11.14% 0.932
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.