High severity8.0NVD Advisory· Published Feb 9, 2018· Updated Jun 17, 2026
CVE-2018-6508
CVE-2018-6508
Description
Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.
Affected products
8cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*range: >=2017.3.0,<=2017.3.2
- (no CPE)range: >=2017.3.0, <2017.3.3
- (no CPE)range: 2017.3.x prior to 2017.3.4
prior to 2.3.1+ 1 more
- (no CPE)range: prior to 2.3.1
- (no CPE)range: prior to 4.5.1
- Puppet/puppetlabs/facter_taskv5Range: prior to 0.1.5
- Range: prior to 5.2.1
- Puppet/puppetlabs/puppet_confv5Range: prior to 0.1.5
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/103020nvdThird Party AdvisoryVDB Entry
- puppet.com/security/cve/CVE-2018-6508nvdVendor Advisory
News mentions
0No linked articles in our index yet.