CVE-2013-3567
Publication date 18 June 2013
Last updated 24 July 2024
Ubuntu priority
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
References
Related Ubuntu Security Notices (USN)
- USN-1886-1
- Puppet vulnerability
- 18 June 2013