CVE-2013-4967: Medium severity puppet enterprise vulnerability
Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4967?
CVE-2013-4967 has a moderate severity rating due to the potential exposure of sensitive database passwords.
How do I fix CVE-2013-4967?
To mitigate CVE-2013-4967, upgrade Puppet Enterprise to version 3.0.1 or later.
What versions are affected by CVE-2013-4967?
CVE-2013-4967 affects Puppet Enterprise versions prior to 3.0.1, including 2.5.1, 2.5.2, 2.8.0, 2.8.1, 2.8.2, and 2.8.3.
What are the potential impacts of CVE-2013-4967?
The main impact of CVE-2013-4967 is unauthorized access to the database password, which can lead to further exploitation of the system.
Is CVE-2013-4967 a remote vulnerability?
Yes, CVE-2013-4967 is a remote vulnerability that allows attackers to exploit the system without physical access.