CVE-2018-6513 Information
Feb 14, 2021
cve
Description
Puppet Enterprise 2016.4.x prior to 2016.4.12 Puppet Enterprise 2017.3.x prior to 2017.3.7 Puppet Enterprise 2018.1.x prior to 2018.1.1 Puppet Agent 1.10.x prior to 1.10.13 Puppet Agent 5.3.x prior to 5.3.7 and Puppet Agent 5.5.x prior to 5.5.2 were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet run. This was possible through the loading of shared libraries from untrusted paths.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://puppet.com/security/cve/CVE-2018-6513
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: