CVE-2018-6508

HIGH

Puppet Enterprise < 2017.3.2 - Format String Vulnerability

Title source: rule
STIX 2.1

Description

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

Scores

CVSS v3 8.0
EPSS 0.0091
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-134
Status published
Products (1)
puppet/puppet_enterprise 2017.3.0 - 2017.3.2
Published Feb 09, 2018
Tracked Since Feb 18, 2026