Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://puppet.com/security/cve/cve-2016-5713 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: puppet
Published: 2017-12-06T15:00:00Z
Updated: 2024-09-17T00:06:12.325Z
Reserved: 2016-06-16T00:00:00
Link: CVE-2016-5713
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-12-06T15:29:00.217
Modified: 2024-11-21T02:54:52.493
Link: CVE-2016-5713
Redhat
No data.