CVE-2013-1398: High severity Puppet Puppet Enterprise vulnerability
Published Mar 14, 2014
·Updated
The pemcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.
Affected Software
6 affected components
Puppet Puppet Enterprise<=2.7.0
Puppet Puppet Enterprise=2.0.0
Puppet Puppet Enterprise=2.5.1
Puppet Puppet Enterprise=2.5.2
Puppetlabs Puppet=2.5.0
Puppetlabs Puppet=2.6.0
Event History
Mar 14, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-1398?
CVE-2013-1398 has a moderate severity level due to its potential for unauthorized access to sensitive information.
2
How do I fix CVE-2013-1398?
To fix CVE-2013-1398, upgrade Puppet Enterprise to version 2.7.1 or later.
3
What versions of Puppet Enterprise are affected by CVE-2013-1398?
CVE-2013-1398 affects Puppet Enterprise versions 2.0.0 through 2.7.0.
4
What type of vulnerability is CVE-2013-1398?
CVE-2013-1398 is an access control vulnerability that allows unauthorized information access.
5
Who can exploit CVE-2013-1398?
Remote authenticated users with root access to a node can exploit CVE-2013-1398.