cbcvebase.
CVE-2016-5713
published 2017-12-06

CVE-2016-5713: Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianpuppet< puppet 4.7.0-1 (bullseye)puppet 4.7.0-1 (bullseye)
puppetpuppet>= 0 < 4.7.0-14.7.0-1
puppetpuppet_agent
puppetpuppet_agent>= 1.3.0 < 1.6.01.6.0

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL