CVE-2016-5713: Code Injection
Published Dec 6, 2017
·Updated
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.
Affected Software
1 affected component
Puppet Puppet Agent>=1.3.0<1.6.0
Event History
Dec 6, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2016-5713?
CVE-2016-5713 is a vulnerability in Puppet Agent that allowed unauthorized code to be loaded.
2
What is the severity of CVE-2016-5713?
CVE-2016-5713 has a severity rating of 9.8 (Critical).
3
How does CVE-2016-5713 affect Puppet Agent?
CVE-2016-5713 affects versions of Puppet Agent prior to 1.6.0 and allows unauthorized code to be loaded.
4
How can I fix CVE-2016-5713?
To fix CVE-2016-5713, upgrade to Puppet Agent version 1.6.0 or newer.
5
Is CVE-2016-5713 associated with any CWE?
Yes, CVE-2016-5713 is associated with CWE-94 (Code Injection).