cbcvebase.
CVE-2018-6512
published 2018-06-11

CVE-2018-6512: The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianpuppet
puppetpe-razor-server< 1.9.0.01.9.0.0
puppetpuppet_enterprise>= 2018.1.0 < 2018.1.12018.1.1
puppetrazor-server< 1.9.0.01.9.0.0