CVE-2018-6512

CWE-94Code Injection4 documents4 sources
Severity
9.8CRITICAL
EPSS
1.1%
top 21.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDpuppet/razor-server< 1.9.0.0
NVDpuppet/pe-razor-server< 1.9.0.0
NVDpuppet/puppet_enterprise2018.1.02018.1.1

🔴Vulnerability Details

2
GHSA
GHSA-7mp2-f3vh-j4w4: The previous version of Puppet Enterprise 20182022-05-14
CVEList
CVE-2018-6512: The previous version of Puppet Enterprise 20182018-06-11

📋Vendor Advisories

1
Debian
CVE-2018-6512: puppet - The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code ex...2018