VYPR
Critical severity9.8NVD Advisory· Published Dec 6, 2017· Updated May 13, 2026

CVE-2016-5713

CVE-2016-5713

Description

Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.

Affected products

1
  • Puppet/Puppet Agentv5
    Range: Introduced in 1.3.0, fixed in 1.6.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.