Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-2295

Опубликовано: 05 июл. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 6
CVSS3: 8.2

Описание

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.

РелизСтатусПримечание
artful

not-affected

4.8.2-5ubuntu1
bionic

not-affected

4.8.2-5ubuntu1
cosmic

not-affected

4.8.2-5ubuntu1
devel

not-affected

4.8.2-5ubuntu1
disco

not-affected

4.8.2-5ubuntu1
eoan

not-affected

4.8.2-5ubuntu1
esm-apps/bionic

not-affected

4.8.2-5ubuntu1
esm-apps/focal

not-affected

4.8.2-5ubuntu1
esm-apps/jammy

not-affected

4.8.2-5ubuntu1
esm-apps/xenial

released

3.8.5-2ubuntu0.1+esm1

Показывать по

6 Medium

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
больше 8 лет назад

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.

CVSS3: 8.2
nvd
больше 8 лет назад

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.

CVSS3: 8.2
debian
больше 8 лет назад

Versions of Puppet prior to 4.10.1 will deserialize data off the wire ...

suse-cvrf
больше 8 лет назад

Security update for rubygem-puppet

suse-cvrf
почти 8 лет назад

Security update for puppet

6 Medium

CVSS2

8.2 High

CVSS3