The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated nodes to submit reports for other nodes via unspecified vectors.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/58449 | Third Party Advisory VDB Entry |
http://www.debian.org/security/2013/dsa-2643 | Third Party Advisory |
http://ubuntu.com/usn/usn-1759-1 | Third Party Advisory |
https://puppetlabs.com/security/cve/cve-2013-2275/ | Vendor Advisory |
http://secunia.com/advisories/52596 | Third Party Advisory |
http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html | Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html | Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2013-0710.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Information
Published : 2013-03-20 09:55
Updated : 2019-07-10 11:02
NVD link : CVE-2013-2275
Mitre link : CVE-2013-2275
JSON object : View
CWE
Products Affected
canonical
- ubuntu_linux
puppet
- puppet_enterprise
- puppet
puppetlabs
- puppet