HIGH
GHSA-574q-fxfj-wv6h
Puppet Improper Input Validation vulnerability
Quick fix
GHSA-574q-fxfj-wv6h — puppet: upgrade to the fixed version with the command below.
bundle update puppetDetails
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-1655[ADVISORY]
- https://github.com/puppetlabs/puppet[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2013-1655.yml[WEB]
- https://puppetlabs.com/security/cve/cve-2013-1655[WEB]
- https://web.archive.org/web/20200228144801/http://www.securityfocus.com/bid/58442[WEB]
- https://www.puppet.com/security/cve/cve-2013-1655-unauthenticated-remote-code-execution-vulnerability[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html[WEB]
- http://ubuntu.com/usn/usn-1759-1[WEB]
- http://www.debian.org/security/2013/dsa-2643[WEB]