« Volver al listado

CVE-2018-6508

Estado: ModificadaAlta (8)—

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-6508",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "Puppet",
          "product": "Puppet Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "2017.3.x prior to 2017.3.4"
            }
          ]
        },
        {
          "vendor": "Puppet",
          "product": "puppetlabs/facter_task",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 0.1.5"
            }
          ]
        },
        {
          "vendor": "Puppet",
          "product": "puppetlabs/puppet_conf",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 0.1.5"
            }
          ]
        },
        {
          "vendor": "Puppet",
          "product": "puppetlabs/apt",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 4.5.1"
            }
          ]
        },
        {
          "vendor": "Puppet",
          "product": "puppetlabs/mysql",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 5.2.1"
            }
          ]
        },
        {
          "vendor": "Puppet",
          "product": "puppetlabs/apache",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 2.3.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-09T20:29:00.317",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/103020",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "https://puppet.com/security/cve/CVE-2018-6508",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/103020",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://puppet.com/security/cve/CVE-2018-6508",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-134"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability."
    },
    {
      "lang": "es",
      "value": "Puppet Enterprise 2017.3.x anteriores a 2017.3.3 es vulnerable a un error de ejecución remota cuando una cadena especialmente manipulada se pasaba en las tareas facter_task o puppet_conf. Esta vulnerabilidad solo afecta a tareas en los módulos afectados, por lo que las personas que no usen tareas puppet no se verán afectadas por esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T02:01:56.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78C71EEA-3AB4-48EB-8BD2-C2E649141E33",
              "versionEndIncluding": "2017.3.2",
              "versionStartIncluding": "2017.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@puppet.com"
}