CVE Database
/

CVE-2018-6508

Back to search

CVE-2018-6508

Published: Feb 9, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

VendorProductVersions

Puppet

Puppet Enterprise

affected
2017.3.x prior to 2017.3.4

Puppet

puppetlabs/facter_task

affected
prior to 0.1.5

Puppet

puppetlabs/puppet_conf

affected
prior to 0.1.5

Puppet

puppetlabs/apt

affected
prior to 4.5.1

Puppet

puppetlabs/mysql

affected
prior to 5.2.1

Puppet

puppetlabs/apache

affected
prior to 2.3.1

References

103020
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now