CVE-2013-4966

Puppet Enterprise <3.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029873
Vendor Advisory x_refsource_confirm
http://puppetlabs.com/security/cve/cve-2013-4966

Scores

EPSS 0.0108
EPSS Percentile 61.0%

Details

CWE
CWE-287
Status published
Products (4)
puppet/puppet_enterprise 3.0.0
puppet/puppet_enterprise 3.0.1
puppet/puppet_enterprise 3.1.0
puppet/puppet_enterprise < 3.1.1
Published Mar 09, 2014
Tracked Since Feb 18, 2026