Lucene search

K
cveMitreCVE-2013-1398
HistoryMar 14, 2014 - 4:55 p.m.

CVE-2013-1398

2014-03-1416:55:04
CWE-310
mitre
web.nvd.nist.gov
32
puppet
enterprise
pe
security
cve-2013-1398
vulnerability
ssl keys
remote access
privileges

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

47.6%

The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.

Affected configurations

Nvd
Node
puppetpuppet_enterpriseRange2.7.0
OR
puppetpuppet_enterpriseMatch2.0.0
OR
puppetpuppet_enterpriseMatch2.5.1
OR
puppetpuppet_enterpriseMatch2.5.2
OR
puppetlabspuppetMatch2.5.0-enterprise
OR
puppetlabspuppetMatch2.6.0-enterprise
VendorProductVersionCPE
puppetpuppet_enterprise*cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
puppetpuppet_enterprise2.0.0cpe:2.3:a:puppet:puppet_enterprise:2.0.0:*:*:*:*:*:*:*
puppetpuppet_enterprise2.5.1cpe:2.3:a:puppet:puppet_enterprise:2.5.1:*:*:*:*:*:*:*
puppetpuppet_enterprise2.5.2cpe:2.3:a:puppet:puppet_enterprise:2.5.2:*:*:*:*:*:*:*
puppetlabspuppet2.5.0cpe:2.3:a:puppetlabs:puppet:2.5.0:-:enterprise:*:*:*:*:*
puppetlabspuppet2.6.0cpe:2.3:a:puppetlabs:puppet:2.6.0:-:enterprise:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

47.6%

Related for CVE-2013-1398