CVE-2013-3567

EPSS 5.8%

puppet - code execution

發布日:2017/10/24修改日:2026/4/28

描述

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.

受影響套件(3)

參考連結(12)