CVE-2013-4761

Description

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified local file system access to the Puppet Master.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.62

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-4761 are fixed in Ruby-puppet 2.7.23Windows
Vulnerabilities CVE-2013-4761 are fixed in Ruby-puppet 3.2.4Windows
Vulnerabilities CVE-2013-4761 are fixed in Ruby-puppet for Linux 2.7.23Linux
Vulnerabilities CVE-2013-4761 are fixed in Ruby-puppet for Linux 3.2.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234