Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes.
References
Link | Resource |
---|---|
http://puppetlabs.com/security/cve/cve-2013-4967 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:14:59
Updated: 2022-10-03T16:14:59
Reserved: 2022-10-03T00:00:00
Link: CVE-2013-4967
JSON object: View
NVD Information
Status : Analyzed
Published: 2013-08-20T22:55:04.577
Modified: 2019-07-10T18:10:48.883
Link: CVE-2013-4967
JSON object: View
Redhat Information
No data.
CWE