The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2643-1 | puppet security update |
EUVD |
EUVD-2013-1671 | The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request. |
Ubuntu USN |
USN-1759-1 | Puppet vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T15:13:31.581Z
Reserved: 2013-02-10T00:00:00
Link: CVE-2013-1640
No data.
Status : Deferred
Published: 2013-03-20T16:55:01.723
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-1640
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN