CVE-2018-6512: Code Injection
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
puppet/puppet-enterprise/2018.1/pe-razor-serverto a version that resolves this vulnerability.Fixed in 1.9.0.0 - Upgrade
Upgrade
puppet/puppet-enterprise/2018.1/razor-serverto a version that resolves this vulnerability.Fixed in 1.9.0.0 - Upgrade
Upgrade
puppet/puppet-enterprise/2018.1to a version that resolves this vulnerability.Fixed in 2018.1.1
Event History
Frequently Asked Questions
What is the vulnerability ID of this Puppet Enterprise vulnerability?
The vulnerability ID is CVE-2018-6512.
What is the severity of CVE-2018-6512?
The severity of CVE-2018-6512 is critical with a CVSS score of 9.8.
Which versions of Puppet Enterprise are affected by CVE-2018-6512?
Puppet Enterprise 2018.1.x versions prior to 2018.1.1 are affected by CVE-2018-6512.
Which software components of Puppet Enterprise are affected by CVE-2018-6512?
The software components affected by CVE-2018-6512 are pe-razor-server, razor-server, and pe-razor-server.
How can I fix CVE-2018-6512?
To fix CVE-2018-6512, you should upgrade Puppet Enterprise to version 2018.1.1 or later.