Candidate: CVE-2013-2274 CRD: 2013-03-12 18:00:00 UTC PublicDate: 2013-03-20 16:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2274 Description: Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report. Ubuntu-Description: Notes: Bugs: Priority: high Discovered-by: Assigned-to: CVSS: Patches_puppet: upstream_puppet: released (2.6.18) hardy_puppet: ignored (reached end-of-life) lucid_puppet: not-affected (0.25.4-2ubuntu6.8) oneiric_puppet: not-affected (2.7.1-1ubuntu3.7) precise_puppet: not-affected (2.7.11-1ubuntu2.1) quantal_puppet: not-affected (2.7.18-1ubuntu1) devel_puppet: not-affected (2.7.18-1ubuntu1)