CVE-2013-1652

Puppet < 2.6.18, 2.7.x < 2.7.21, 3.1.x < 3.1.1 - Authenticated Arbitrary Catalog Read or Cache Poisoning

Title source: llm
STIX 2.1

Description

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.

References (8)

Core 8
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0710.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2643
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/58443
Third Party Advisory, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/52596
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-1759-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html
Vendor Advisory x_refsource_confirm
https://puppetlabs.com/security/cve/cve-2013-1652/

Scores

EPSS 0.0186
EPSS Percentile 76.9%

Details

CWE
CWE-264
Status published
Products (28)
canonical/ubuntu_linux 11.10
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
puppet/puppet 2.7.2
puppet/puppet 2.7.3
puppet/puppet 2.7.4
puppet/puppet 2.7.5
puppet/puppet 2.7.6
puppet/puppet 2.7.7
puppet/puppet 2.7.8
... and 18 more
Published Mar 20, 2013
Tracked Since Feb 18, 2026