CVE-2013-4761

medium
Published 2017-10-24 · Modified 2024-11-29
CVSS v3
CVSS v2
5.1
VIR risk
5.1

Description

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4761

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://puppetlabs.com/security/cve/cve-2013-4761/

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed3.2.4-1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemspuppet!< 2.7.0||<~> 2.7.23~> 2.7.23
ruby RubyGemspuppet>=2.7.0,<2.7.232.7.23
ruby RubyGemspuppet>=3.2.0,<3.2.43.2.4

Application impact

VendorProductVersionsFixed
puppetpuppet3.2.1
puppetpuppet3.2.2
puppetpuppet3.2.3
puppetlabspuppet3.2.0
puppetpuppet2.7.2
puppetlabspuppet2.7.0
puppetlabspuppet2.7.1
puppetpuppet_enterprise2.8.0
puppetpuppet_enterprise2.8.1
puppetpuppet_enterprise2.8.2
puppetpuppet_enterprise3.0.0

References

Verify integrity in audit chain (admin only). AS-IS.