VendorsPuppet Labspuppet2.7.2
Vulnerabilities

Puppet Labs Puppetlabs Puppet 2.7.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2013-3567
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Published 2013-08-19 · Modified
7.5EPSS 0.034