CVE-2013-3567 describes a critical vulnerability in Puppet 2.7.x before 2.7.22, 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, affecting products from Canonical, Novell, and Puppet Labs. This flaw allows remote attackers to execute arbitrary code by exploiting insecure deserialization of untrusted YAML via a crafted REST API call. With a CVSS score of 7.5, it represents a high-severity vulnerability with low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the KEV catalog or readily available public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7.2CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:* | ||
2.7.10CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:* | ||
2.7.11CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.11:*:*:*:*:*:*:* | ||
2.7.12CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.12:*:*:*:*:*:*:* | ||
2.7.13CPE matchmatch criteria | cpe:2.3:a:puppet:puppet:2.7.13:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.