VDB

CVE-2018-6508

CVE-2018-6508 PUBLISHED

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

EPSS 0.91% · 76.1th percentile

Risk Scores

EPSS Score
0.91%
76.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSpuppet-module-puppetlabs-apache3.4.0-1, 0
Ubuntu:16.04:LTSpuppet-module-puppetlabs-apt2.2.0-1, 0, 1.6.0-2
Ubuntu:22.04:LTSpuppet-module-puppetlabs-apt0, 6.1.1-1
Ubuntu:25.10puppet-module-puppetlabs-mysql0, 8.1.0-7ubuntu1
Ubuntu:22.04:LTSpuppet-module-puppetlabs-mysql8.1.0-5ubuntu1, 0
Ubuntu:22.04:LTSpuppet-module-puppetlabs-apache5.5.0-2, 0
Ubuntu:16.04:LTSpuppet-module-puppetlabs-mysql0, 2.3.1-1, 3.6.1-1
Ubuntu:18.04:LTSpuppet-module-puppetlabs-apache0, 3.0.0-1, 1.10.0-1
Ubuntu:25.10puppet-module-puppetlabs-apache0, 12.2.0-1
Ubuntu:18.04:LTSpuppet-module-puppetlabs-apt0, 2.3.0-1, 4.4.1-1
Ubuntu:16.04:LTSpuppet-module-puppetlabs-apache1.1.1-1, 0, 1.6.0-1
Ubuntu:24.04:LTSpuppet-module-puppetlabs-apache12.0.2-1, 0, 5.5.0-2
Ubuntu:20.04:LTSpuppet-module-puppetlabs-apt0, 6.1.1-1
Ubuntu:18.04:LTSpuppet-module-puppetlabs-mysql0, 3.10.0-1
Ubuntu:25.10puppet-module-puppetlabs-apt9.4.0-1, 0
Ubuntu:24.04:LTSpuppet-module-puppetlabs-apt9.4.0-1, 0, 9.0.1-1
Ubuntu:24.04:LTSpuppet-module-puppetlabs-mysql8.1.0-7ubuntu1, 0
Ubuntu:20.04:LTSpuppet-module-puppetlabs-mysql5.3.0-1ubuntu1, 0, 8.1.0-2ubuntu1

Exploit Intelligence

Timeline

  • Feb 9, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›