CVE-2013-1652: Medium severity puppet vulnerability
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1652?
CVE-2013-1652 is considered a critical vulnerability due to its potential to allow remote authenticated users to read arbitrary catalogs or poison the master's cache.
How do I fix CVE-2013-1652?
To fix CVE-2013-1652, upgrade to Puppet 2.6.18 or higher, Puppet 2.7.21 or higher, or Puppet Enterprise 1.2.7 or higher.
Who is affected by CVE-2013-1652?
CVE-2013-1652 affects users of Puppet versions prior to 2.6.18, 2.7.x prior to 2.7.21, and 3.1.x prior to 3.1.1.
What type of access does CVE-2013-1652 allow?
CVE-2013-1652 allows remote authenticated users with a valid certificate and private key to configure Puppet master behaviors.
Is there a workaround for CVE-2013-1652?
There are no known workarounds for CVE-2013-1652; the recommended course of action is to apply the necessary updates.