Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-2274

Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 82.2%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2013-2274
  • Puppet » Puppet » Version: 2.6.0
    cpe:2.3:a:puppet:puppet:2.6.0
  • Puppet » Puppet » Version: 2.6.1
    cpe:2.3:a:puppet:puppet:2.6.1
  • Puppet » Puppet » Version: 2.6.10
    cpe:2.3:a:puppet:puppet:2.6.10
  • Puppet » Puppet » Version: 2.6.11
    cpe:2.3:a:puppet:puppet:2.6.11
  • Puppet » Puppet » Version: 2.6.12
    cpe:2.3:a:puppet:puppet:2.6.12
  • Puppet » Puppet » Version: 2.6.13
    cpe:2.3:a:puppet:puppet:2.6.13
  • Puppet » Puppet » Version: 2.6.14
    cpe:2.3:a:puppet:puppet:2.6.14
  • Puppet » Puppet » Version: 2.6.15
    cpe:2.3:a:puppet:puppet:2.6.15
  • Puppet » Puppet » Version: 2.6.16
    cpe:2.3:a:puppet:puppet:2.6.16
  • Puppet » Puppet » Version: 2.6.2
    cpe:2.3:a:puppet:puppet:2.6.2
  • Puppet » Puppet » Version: 2.6.3
    cpe:2.3:a:puppet:puppet:2.6.3
  • Puppet » Puppet » Version: 2.6.4
    cpe:2.3:a:puppet:puppet:2.6.4
  • Puppet » Puppet » Version: 2.6.5
    cpe:2.3:a:puppet:puppet:2.6.5
  • Puppet » Puppet » Version: 2.6.6
    cpe:2.3:a:puppet:puppet:2.6.6
  • Puppet » Puppet » Version: 2.6.7
    cpe:2.3:a:puppet:puppet:2.6.7
  • Puppet » Puppet » Version: 2.6.8
    cpe:2.3:a:puppet:puppet:2.6.8
  • Puppet » Puppet » Version: 2.6.9
    cpe:2.3:a:puppet:puppet:2.6.9
  • Puppet » Puppet Enterprise » Version: 1.2.0
    cpe:2.3:a:puppet:puppet_enterprise:1.2.0
  • Puppetlabs » Puppet » Version: 2.6.17
    cpe:2.3:a:puppetlabs:puppet:2.6.17


Contact Us

Shodan ® - All rights reserved