Field Assessment
AI analysis pending.
CVE
CVE-2013-2274
Severity
MEDIUM
CVSS
6.5
EPSS
2.91%
Original Filing — NVD Description
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.