CVE-2013-3567
published 2013-08-19CVE-2013-3567: Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to…
PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.41%
87.5th percentile
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | puppet | < puppet 3.2.2-1 (bullseye) | puppet 3.2.2-1 (bullseye) |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_server | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 3.2.2-1 | 3.2.2-1 |
| puppet | puppet | >= 2.7.0 < 2.7.22 | 2.7.22 |
| puppet | puppet | >= 3.2.0 < 3.2.2 | 3.2.2 |
| puppet | puppet_enterprise | <= 2.8.1 | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerability
vendor_ubuntu·2013-06-18
CVE-2013-3567 Puppet vulnerability
Title: Puppet vulnerability
Summary: Puppet could be made to run programs if it received specially crafted
network traffic.
It was discovered that Puppet incorrectly handled YAML payloads. An
attacker on an untrusted client could use this issue to execute arbitrary
code on the primary server.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
puppet: remote code execution on master from unauthenticated clients
vendor_redhat·2013-06-18·CVSS 7.5
CVE-2013-3567 [HIGH] CWE-502 puppet: remote code execution on master from unauthenticated clients
puppet: remote code execution on master from unauthenticated clients
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Package: puppet (Red Hat Enterprise MRG 1) - Under investigation
Package: puppet (Red Hat OpenStack Platform 4) - Affected
Package: puppet (Red Hat Subscription Asset Manager) - Affected
Debian
CVE-2013-3567: puppet - Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before ...
vendor_debian·2013·CVSS 7.5
CVE-2013-3567 [HIGH] CVE-2013-3567: puppet - Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before ...
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Scope: local
bullseye: resolved (fixed in 3.2.2-1)
GHSA
Puppet Improper Input Validation vulnerability
ghsa·2017-10-24
CVE-2013-3567 [HIGH] CWE-20 Puppet Improper Input Validation vulnerability
Puppet Improper Input Validation vulnerability
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
OSV
Puppet Improper Input Validation vulnerability
osv·2017-10-24
CVE-2013-3567 [HIGH] Puppet Improper Input Validation vulnerability
Puppet Improper Input Validation vulnerability
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
OSV
CVE-2013-3567: Puppet 2
osv·2013-08-19·CVSS 7.5
CVE-2013-3567 [HIGH] CVE-2013-3567: Puppet 2
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients [fedora-all]
bugzilla·2013-06-19·CVSS 7.5
CVE-2013-3567 [HIGH] CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients [fedora-all]
CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please no
Bugzilla
CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients [epel-all]
bugzilla·2013-06-19·CVSS 7.5
CVE-2013-3567 [HIGH] CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients [epel-all]
CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients
bugzilla·2013-06-14·CVSS 7.5
CVE-2013-3567 [HIGH] CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients
CVE-2013-3567 puppet: remote code execution on master from unauthenticated clients
When making REST api calls, the puppet master takes YAML from an untrusted
client, deserializes it, and then calls methods on the resulting object. A YAML
payload can be crafted to cause the deserialization to construct an instance of
any class available in the ruby process, which allows an attacker to execute
code contained in the payload.
Discussion:
External Reference:
http://puppetlabs.com/security/cve/cve-2013-3567/
---
Created puppet tracking bugs for this issue
Affects: fedora-all [bug 975814]
Affects: epel-all [bug 975816]
---
The Red Hat Security Response Team has rated this issue as having moderate security impact in CloudForms 1.1. This issue is not currently planned to be addressed in fu
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1283.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1284.htmlhttp://secunia.com/advisories/54429http://www.debian.org/security/2013/dsa-2715http://www.ubuntu.com/usn/USN-1886-1https://puppetlabs.com/security/cve/cve-2013-3567/http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1283.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1284.htmlhttp://secunia.com/advisories/54429http://www.debian.org/security/2013/dsa-2715http://www.ubuntu.com/usn/USN-1886-1https://puppetlabs.com/security/cve/cve-2013-3567/
2013-08-19
Published