Lucene search

K
cve[email protected]CVE-2013-1653
HistoryMar 20, 2013 - 4:55 p.m.

CVE-2013-1653

2013-03-2016:55:01
web.nvd.nist.gov
44
puppet
cve-2013-1653
remote code execution
information security
vulnerability

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.7%

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the “run” REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.

Affected configurations

NVD
Node
puppetpuppetRange2.6.02.6.17
Node
puppetpuppetMatch2.7.2
OR
puppetpuppetMatch2.7.3
OR
puppetpuppetMatch2.7.4
OR
puppetpuppetMatch2.7.5
OR
puppetpuppetMatch2.7.6
OR
puppetpuppetMatch2.7.7
OR
puppetpuppetMatch2.7.8
OR
puppetpuppetMatch2.7.9
OR
puppetpuppetMatch2.7.10
OR
puppetpuppetMatch2.7.11
OR
puppetpuppetMatch2.7.12
OR
puppetpuppetMatch2.7.13
OR
puppetpuppetMatch2.7.14
OR
puppetpuppetMatch2.7.16
OR
puppetpuppetMatch2.7.17
OR
puppetpuppetMatch2.7.18
OR
puppetlabspuppetMatch2.7.0
OR
puppetlabspuppetMatch2.7.1
OR
puppetlabspuppetMatch2.7.19
OR
puppetlabspuppetMatch2.7.20
OR
puppetlabspuppetMatch2.7.20rc1
Node
puppetpuppet_enterpriseMatch3.1.0
Node
puppetlabspuppetMatch1.0enterprise
OR
puppetlabspuppetMatch1.1enterprise
OR
puppetlabspuppetMatch1.2.0enterprise
OR
puppetlabspuppetMatch1.2.1enterprise
OR
puppetlabspuppetMatch1.2.2enterprise
OR
puppetlabspuppetMatch1.2.3enterprise
OR
puppetlabspuppetMatch1.2.4enterprise
OR
puppetlabspuppetMatch1.2.5enterprise
OR
puppetlabspuppetMatch1.2.6enterprise
Node
puppetpuppet_enterpriseMatch2.7.0
OR
puppetpuppet_enterpriseMatch2.7.1
Node
canonicalubuntu_linuxMatch11.10
OR
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch12.10
CPENameOperatorVersion
puppet:puppetpuppetle2.6.17

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.7%