VDB
DEBIAN-CVE-2013-1653
DEBIAN-CVE-2013-1653
PUBLISHED
CVSS 8.600000381469727 HIGH
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
Risk Scores
CVSS v4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | puppet | 0, 0, 0 |
Timeline
- Mar 20, 2013 CVE Published
- Apr 28, 2026 CVE Updated