5.1

CVE-2013-4761

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service.  NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppet ≫ Puppet Version 3.2.1
Puppet ≫ Puppet Version 3.2.2
Puppet ≫ Puppet Version 3.2.3
Puppetlabs ≫ Puppet Version 3.2.0
Puppet ≫ Puppet Version 2.7.2
Puppetlabs ≫ Puppet Version 2.7.0
Puppetlabs ≫ Puppet Version 2.7.1
Puppet ≫ Puppet Enterprise Version 2.8.0
Puppet ≫ Puppet Enterprise Version 2.8.1
Puppet ≫ Puppet Enterprise Version 2.8.2
Puppet ≫ Puppet Enterprise Version 3.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.64% 0.733
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://rhn.redhat.com/errata/RHSA-2013-1283.html
http://rhn.redhat.com/errata/RHSA-2013-1284.html
http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00009.html
http://puppetlabs.com/security/cve/cve-2013-4761/
Vendor Advisory
http://www.debian.org/security/2013/dsa-2761