Lucene search

K
cve[email protected]CVE-2013-1655
HistoryMar 20, 2013 - 4:55 p.m.

CVE-2013-1655

2013-03-2016:55:01
CWE-20
web.nvd.nist.gov
74
cve-2013-1655
puppet
remote code execution
serialized attributes
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.096 Low

EPSS

Percentile

94.8%

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to “serialized attributes.”

Affected configurations

NVD
Node
puppetpuppetMatch2.7.2
OR
puppetpuppetMatch2.7.3
OR
puppetpuppetMatch2.7.4
OR
puppetpuppetMatch2.7.5
OR
puppetpuppetMatch2.7.6
OR
puppetpuppetMatch2.7.7
OR
puppetpuppetMatch2.7.8
OR
puppetpuppetMatch2.7.9
OR
puppetpuppetMatch2.7.10
OR
puppetpuppetMatch2.7.11
OR
puppetpuppetMatch2.7.12
OR
puppetpuppetMatch2.7.13
OR
puppetpuppetMatch2.7.14
OR
puppetpuppetMatch2.7.16
OR
puppetpuppetMatch2.7.17
OR
puppetpuppetMatch2.7.18
OR
puppetpuppet_enterpriseMatch3.1.0
OR
puppetlabspuppetMatch2.7.0
OR
puppetlabspuppetMatch2.7.1
OR
puppetlabspuppetMatch2.7.19
OR
puppetlabspuppetMatch2.7.20
OR
puppetlabspuppetMatch2.7.20rc1
AND
ruby-langrubyMatch1.9
OR
ruby-langrubyMatch1.9.1
OR
ruby-langrubyMatch1.9.2
OR
ruby-langrubyMatch1.9.3
OR
ruby-langrubyMatch1.9.3p0
OR
ruby-langrubyMatch1.9.3p125
OR
ruby-langrubyMatch1.9.3p194
OR
ruby-langrubyMatch1.9.3p286
OR
ruby-langrubyMatch1.9.3p383
OR
ruby-langrubyMatch2.0
OR
ruby-langrubyMatch2.0.0
OR
ruby-langrubyMatch2.0.0rc1
OR
ruby-langrubyMatch2.0.0rc2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.096 Low

EPSS

Percentile

94.8%