CVE-2013-1652
4.9
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:N
Exploitability: 6.8 / Impact: 4.9
Source: NVD
Description
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.
Affected (29)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6.17 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.7.10 | |
| Version 2.7.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.1.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.6 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.7.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.10 |
Related CWEs
References (16)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.