Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-18264 Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: puppet

Published:

Updated: 2024-09-17T01:55:41.774Z

Reserved: 2018-02-01T00:00:00

Link: CVE-2018-6508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-09T20:29:00.317

Modified: 2024-11-21T04:10:47.917

Link: CVE-2018-6508

cve-icon Redhat

Severity : Important

Publid Date: 2018-02-05T00:00:00Z

Links: CVE-2018-6508 - Bugzilla

cve-icon OpenCVE Enrichment

No data.