Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: puppet

Published: 2017-12-06T15:00:00Z

Updated: 2024-09-17T00:06:12.325Z

Reserved: 2016-06-16T00:00:00

Link: CVE-2016-5713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-12-06T15:29:00.217

Modified: 2017-12-28T17:50:38.620

Link: CVE-2016-5713

cve-icon Redhat

No data.