CVE-2013-4957: Code Injection
Published Oct 25, 2013
·Updated
The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type.
Affected Software
7 affected components
puppet Puppet Enterprise<=3.0.0
puppet Puppet Enterprise=2.5.1
puppet Puppet Enterprise=2.5.2
puppet Puppet Enterprise=2.8.0
puppet Puppet Enterprise=2.8.1
puppet Puppet Enterprise=2.8.2
puppet Puppet Enterprise=2.8.3
Event History
Oct 25, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4957?
CVE-2013-4957 is classified as a high severity vulnerability due to the potential for attackers to execute arbitrary code.
2
How do I fix CVE-2013-4957?
To fix CVE-2013-4957, upgrade to Puppet Enterprise version 3.0.1 or later.
3
What types of attacks can CVE-2013-4957 facilitate?
CVE-2013-4957 can facilitate arbitrary code execution due to inadequate input validation in the dashboard report.
4
Which versions of Puppet Enterprise are affected by CVE-2013-4957?
Puppet Enterprise versions prior to 3.0.1 and specifically 2.5.1, 2.5.2, 2.8.0, 2.8.1, 2.8.2, and 2.8.3 are affected by CVE-2013-4957.
5
Is CVE-2013-4957 exploitable remotely?
Yes, CVE-2013-4957 is exploitable remotely, allowing unauthorized users to execute malicious code.