CVE-2013-2274: Medium severity puppet vulnerability
Published Mar 20, 2013
·Updated
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.
Affected Software
19 affected components
Puppet Puppet=2.6.0
Puppet Puppet=2.6.1
Puppet Puppet=2.6.2
Puppet Puppet=2.6.3
Puppet Puppet=2.6.4
Puppet Puppet=2.6.5
Puppet Puppet=2.6.6
Puppet Puppet=2.6.7
Puppet Puppet=2.6.8
Puppet Puppet=2.6.9
Puppet Puppet=2.6.10
Puppet Puppet=2.6.11
Puppet Puppet=2.6.12
Puppet Puppet=2.6.13
Puppet Puppet=2.6.14
Puppet Puppet=2.6.15
Puppet Puppet=2.6.16
Puppetlabs Puppet=2.6.17
Puppet Puppet Enterprise=1.2.0
Event History
Mar 20, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2274?
CVE-2013-2274 has a high severity rating due to its potential for remote code execution by authenticated users.
2
How do I fix CVE-2013-2274?
To mitigate CVE-2013-2274, upgrade Puppet to version 2.6.18 or Puppet Enterprise to version 1.2.7 or higher.
3
What versions are affected by CVE-2013-2274?
CVE-2013-2274 affects Puppet versions 2.6.0 to 2.6.17 and Puppet Enterprise versions 1.2.0 to 1.2.6.
4
What type of vulnerability is CVE-2013-2274?
CVE-2013-2274 is categorized as a remote code execution vulnerability.
5
Can unprivileged users exploit CVE-2013-2274?
No, exploitation of CVE-2013-2274 requires authentication, allowing only remote authenticated users to attack.