Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2013-08-20T22:00:00

Updated: 2014-02-26T13:57:01

Reserved: 2013-07-05T00:00:00


Link: CVE-2013-4761

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2013-08-20T22:55:04.297

Modified: 2019-07-10T18:10:44.823


Link: CVE-2013-4761

JSON object: View

cve-icon Redhat Information

No data.