Skip to content

CVE-2013-4966

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0022 (0.2%)
Percentile: 44.8%
EPSS: 2026-05-06

Affects

puppet:puppet_enterprise

Technical description

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

Published: 3/9/2014, 1:16:56 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam