5.5
CVE-2017-2293
- EPSS 0.23%
- Published 01.02.2018 22:29:00
- Last modified 21.11.2024 03:23:13
- Source security@puppet.com
- Teams watchlist Login
- Open Login
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who rely on this functionality can change this policy.
Data is provided by the National Vulnerability Database (NVD)
Puppet ≫ Puppet Enterprise Version < 2016.4.5
Puppet ≫ Puppet Enterprise Version2016.5.1
Puppet ≫ Puppet Enterprise Version2016.5.2
Puppet ≫ Puppet Enterprise Version2017.1.0
Puppet ≫ Puppet Enterprise Version2017.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.422 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:P
|