5.5
CVE-2017-2293
- EPSS 0.23%
- Veröffentlicht 01.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:13
- Quelle security@puppet.com
- Teams Watchlist Login
- Unerledigt Login
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who rely on this functionality can change this policy.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppet ≫ Puppet Enterprise Version < 2016.4.5
Puppet ≫ Puppet Enterprise Version2016.5.1
Puppet ≫ Puppet Enterprise Version2016.5.2
Puppet ≫ Puppet Enterprise Version2017.1.0
Puppet ≫ Puppet Enterprise Version2017.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.422 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:P
|