CVE-2013-1653: High severity puppet vulnerability
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1653?
CVE-2013-1653 has a medium severity level, as it allows remote authenticated users to execute arbitrary code.
How do I fix CVE-2013-1653?
To fix CVE-2013-1653, upgrade Puppet to the latest version that addresses this vulnerability.
Which versions of Puppet are affected by CVE-2013-1653?
CVE-2013-1653 affects Puppet versions before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1.
Is Puppet Enterprise affected by CVE-2013-1653?
Yes, Puppet Enterprise versions before 1.2.7 and 2.7.x before 2.7.2 are affected by CVE-2013-1653.
What are the potential impacts of CVE-2013-1653?
The impact of CVE-2013-1653 includes the possibility for remote authenticated users to execute arbitrary code, compromising system integrity.