CVE-2018-6515: Input Validation
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Puppet Agentto a version that resolves this vulnerability.Fixed in 1.10.13 - Upgrade
Upgrade
Puppet Agentto a version that resolves this vulnerability.Fixed in 5.3.7 - Upgrade
Upgrade
Puppet Agentto a version that resolves this vulnerability.Fixed in 5.5.2
Event History
Frequently Asked Questions
What is CVE-2018-6515?
CVE-2018-6515 is a vulnerability in Puppet Agent that allows an attacker to load arbitrary code with privilege escalation.
What software versions are affected by CVE-2018-6515?
Puppet Agent versions 1.10.x prior to 1.10.13, 5.3.x prior to 5.3.7, and 5.5.x prior to 5.5.2 on Windows only.
How can an attacker exploit CVE-2018-6515?
An attacker can exploit CVE-2018-6515 by using a specially crafted configuration file to get pxp-agent to load arbitrary code with privilege escalation.
What is the severity of CVE-2018-6515?
The severity of CVE-2018-6515 is classified as high, with a severity value of 7.8.
How do I fix CVE-2018-6515?
To fix CVE-2018-6515, update Puppet Agent to version 1.10.13, 5.3.7, or 5.5.2, depending on the affected version.