CVE-2013-1655: Input Validation
Published Mar 20, 2013
·Updated
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."
Affected Software
37 affected componentsFixes available
rubygems/puppet>=2.7.0<2.7.21
2.7.21
rubygems/puppet>=3.1.0<3.1.1
3.1.1
Puppet Puppet=2.7.2
Puppet Puppet=2.7.3
Puppet Puppet=2.7.4
Puppet Puppet=2.7.5
Puppet Puppet=2.7.6
Puppet Puppet=2.7.7
Puppet Puppet=2.7.8
Puppet Puppet=2.7.9
Puppet Puppet=2.7.10
Puppet Puppet=2.7.11
Puppet Puppet=2.7.12
Puppet Puppet=2.7.13
Puppet Puppet=2.7.14
Puppet Puppet=2.7.16
Puppet Puppet=2.7.17
Puppet Puppet=2.7.18
Puppet Puppet Enterprise=3.1.0
Puppetlabs Puppet=2.7.0
Puppetlabs Puppet=2.7.1
Puppetlabs Puppet=2.7.19
Puppetlabs Puppet=2.7.20
Puppetlabs Puppet=2.7.20-rc1
ruby-lang Ruby=1.9
ruby-lang Ruby=1.9.1
ruby-lang Ruby=1.9.2
ruby-lang Ruby=1.9.3
ruby-lang Ruby=1.9.3-p0
ruby-lang Ruby=1.9.3-p125
ruby-lang Ruby=1.9.3-p194
ruby-lang Ruby=1.9.3-p286
ruby-lang Ruby=1.9.3-p383
ruby-lang Ruby=2.0
ruby-lang Ruby=2.0.0
ruby-lang Ruby=2.0.0-rc1
ruby-lang Ruby=2.0.0-rc2
Event History
Mar 20, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Oct 24, 2017
Advisory Published
06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2013-1655?
CVE-2013-1655 has a CVSS score that indicates it is a high severity vulnerability allowing remote code execution.
2
How do I fix CVE-2013-1655?
To fix CVE-2013-1655, upgrade Puppet to version 2.7.21 or 3.1.1 or later.
3
What software is affected by CVE-2013-1655?
CVE-2013-1655 affects Puppet versions 2.7.x before 2.7.21 and 3.1.x before 3.1.1 when running Ruby 1.9.3 or later.
4
What types of attacks are possible with CVE-2013-1655?
CVE-2013-1655 allows remote attackers to execute arbitrary code on the affected Puppet installations.
5
When was CVE-2013-1655 discovered?
CVE-2013-1655 was publicly disclosed in early 2013.