Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27017

Опубликовано: 10 фев. 2021
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

A flaw was found in puppet-agent. Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6puppet-agentNot affected
Red Hat Update Infrastructure 3 for Cloud ProviderspuppetWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1927502puppet-agent: Deserialization of untrusted data

EPSS

Процентиль: 46%
0.00236
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
12 месяцев назад

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

CVSS3: 6.6
nvd
12 месяцев назад

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

CVSS3: 6.6
debian
12 месяцев назад

Utilization of a module presented a security risk by allowing the dese ...

CVSS3: 6.6
github
12 месяцев назад

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

EPSS

Процентиль: 46%
0.00236
Низкий

6.6 Medium

CVSS3