CVE-2013-1655
Puppet Improper Input Validation vulnerability
EPSS 0.54%
Description
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."
How to fix CVE-2013-1655
To remediate CVE-2013-1655, upgrade the affected package to a fixed version below.
- Debian/puppet—upgrade to 2.7.18-3 or later
- RubyGems/puppet—upgrade to 2.7.21 or later
Is CVE-2013-1655 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.7.18-3
- >= 2.7.0, < 2.7.21