This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.
A web application on the remote host is affected by multiple
According to its self-reported version number, the Puppet Enterprise
install on the remote host is a version prior to 3.1.0. As a result,
it is reportedly affected by multiple vulnerabilities :
- An error exists related to the Fiddle and DL modules,
'$SAFE' level verification and object handling that
could allow an attacker to modify system calls.
- A remote code execution vulnerability exists that is
triggered when handling a YAML report. This could allow
a remote attacker to execute arbitrary code.
- A console account brute-force vulnerability exists that
could allow an attacker to brute-force a known user's
- A RubyGems algorithmic complexity denial of service
vulnerability exists that could allow an attacker to
cause a denial of service through CPU consumption.
See also :
Upgrade to Puppet Enterprise 3.1.0 or later.
Risk factor :
Medium / CVSS Base Score : 6.8
CVSS Temporal Score : 5.9
Public Exploit Available : false
Family: CGI abuses
Nessus Plugin ID: 70684 ()
Bugtraq ID: 59881622816317363386
CVE ID: CVE-2013-2065CVE-2013-4287CVE-2013-4957CVE-2013-4965
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.