Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj43-9h3w-v976

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.

Пакеты

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.23

2.7.23

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 3.2.0, < 3.2.4

3.2.4

EPSS

Процентиль: 70%
0.0062
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.

redhat
больше 12 лет назад

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.

nvd
больше 12 лет назад

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.

debian
больше 12 лет назад

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x befo ...

suse-cvrf
больше 11 лет назад

Security update for puppet

EPSS

Процентиль: 70%
0.0062
Низкий