CVE-2013-4761
Summary
| CVE | CVE-2013-4761 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-20 22:55:00 UTC |
| Updated | 2019-07-10 18:10:00 UTC |
| Description | Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Puppet | Puppet | 2.7.2 | All | All | All |
| Application | Puppet | Puppet | 3.2.1 | All | All | All |
| Application | Puppet | Puppet | 3.2.2 | All | All | All |
| Application | Puppet | Puppet | 3.2.3 | All | All | All |
| Application | Puppet | Puppet | 2.7.2 | All | All | All |
| Application | Puppet | Puppet | 3.2.1 | All | All | All |
| Application | Puppet | Puppet | 3.2.2 | All | All | All |
| Application | Puppet | Puppet | 3.2.3 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2.8.0 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2.8.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2.8.2 | All | All | All |
| Application | Puppet | Puppet Enterprise | 3.0.0 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2.8.0 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2.8.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2.8.2 | All | All | All |
| Application | Puppet | Puppet Enterprise | 3.0.0 | All | All | All |
| Application | Puppetlabs | Puppet | 2.7.0 | All | All | All |
| Application | Puppetlabs | Puppet | 2.7.1 | All | All | All |
| Application | Puppetlabs | Puppet | 3.2.0 | All | All | All |
| Application | Puppetlabs | Puppet | 2.7.0 | All | All | All |
| Application | Puppetlabs | Puppet | 2.7.1 | All | All | All |
| Application | Puppetlabs | Puppet | 3.2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE-SU-2014:0155-1: important: Security update for | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2761-1 puppet | DEBIAN | www.debian.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| CVE-2013-4761 | Puppet Labs | CONFIRM | puppetlabs.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.