HIGH
GHSA-f7p5-w2cr-7cp7
Puppet Improper Input Validation vulnerability
Quick fix
GHSA-f7p5-w2cr-7cp7 — puppet: upgrade to the fixed version with the command below.
bundle update puppetDetails
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-3567[ADVISORY]
- https://github.com/puppetlabs/puppet[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2013-3567.yml[WEB]
- https://puppetlabs.com/security/cve/cve-2013-3567[WEB]
- https://www.puppet.com/security/cve/cve-2013-3567-unauthenticated-remote-code-execution-vulnerability[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00002.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00019.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-1283.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-1284.html[WEB]
- http://www.debian.org/security/2013/dsa-2715[WEB]
- http://www.ubuntu.com/usn/USN-1886-1[WEB]