CVE-2018-6508

Source
https://cve.org/CVERecord?id=CVE-2018-6508
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6508.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-6508
Downstream
Published
2018-02-09T20:29:00.317Z
Modified
2026-03-15T21:45:09.076749Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the factertask or puppetconf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6508.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "2017.3.0"
            },
            {
                "last_affected": "2017.3.2"
            }
        ]
    }
]