VDB

GCVE-110-MAGEIA-2013-187

GCVE-110-MAGEIA-2013-187
Advisory Published
Vulnetix · Advisory published June 26, 2013
When making REST api calls, the puppet master takes YAML from an untrusted client, deserializes it, and then calls methods on the resulting object. A YAML payload can be crafted to cause the deserialization to construct an instance of any class available in the ruby process, which allows an attacker to execute code contained in the payload.

Affected Products

VendorProductVersionsPlatforms
Mageiapuppet0 (affected), 2.7.22-1.mga2 (unaffected)
Mageiapuppet0 (affected), 2.7.22-1.mga3 (unaffected)
Mageiapuppet30 (affected), 3.2.2-1.mga3 (unaffected)

Browse GCVE Records

75,294 records in the GCVE database · Updated July 30, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›