VYPR
High severity8.0NVD Advisory· Published Feb 9, 2018· Updated Jun 17, 2026

CVE-2018-6508

CVE-2018-6508

Description

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

Affected products

8
  • cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*range: >=2017.3.0,<=2017.3.2
    • (no CPE)range: >=2017.3.0, <2017.3.3
    • (no CPE)range: 2017.3.x prior to 2017.3.4
  • Puppet (software)/apachecpe-rescue2 versions
    prior to 2.3.1+ 1 more
    • (no CPE)range: prior to 2.3.1
    • (no CPE)range: prior to 4.5.1
  • Puppet/puppetlabs/facter_taskv5
    Range: prior to 0.1.5
  • Range: prior to 5.2.1
  • Puppet/puppetlabs/puppet_confv5
    Range: prior to 0.1.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.