CVE-2013-4761: Medium severity puppet vulnerability
Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resourcetype service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4761?
CVE-2013-4761 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2013-4761?
To fix CVE-2013-4761, upgrade Puppet to version 3.2.4 or 2.7.23 and ensure you are on a supported release.
Which versions of Puppet are affected by CVE-2013-4761?
CVE-2013-4761 affects Puppet versions 2.7.x before 2.7.23, 3.2.x before 3.2.4, Puppet Enterprise 2.8.x before 2.8.3, and 3.0.x before 3.0.1.
Can CVE-2013-4761 be exploited without authentication?
Yes, CVE-2013-4761 can be exploited by remote attackers without authentication.
What types of attacks are possible due to CVE-2013-4761?
Due to CVE-2013-4761, attackers can execute arbitrary Ruby programs on the Puppet master.