Total vulnerabilities in the database
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."
Software | From | Fixed in |
---|---|---|
puppet / puppet | 2.7.2 | 2.7.2.x |
puppet / puppet | 2.7.3 | 2.7.3.x |
puppet / puppet | 2.7.4 | 2.7.4.x |
puppet / puppet | 2.7.5 | 2.7.5.x |
puppet / puppet | 2.7.6 | 2.7.6.x |
puppet / puppet | 2.7.7 | 2.7.7.x |
puppet / puppet | 2.7.8 | 2.7.8.x |
puppet / puppet | 2.7.9 | 2.7.9.x |
puppet / puppet | 2.7.10 | 2.7.10.x |
puppet / puppet | 2.7.11 | 2.7.11.x |
puppet / puppet | 2.7.12 | 2.7.12.x |
puppet / puppet | 2.7.13 | 2.7.13.x |
puppet / puppet | 2.7.14 | 2.7.14.x |
puppet / puppet | 2.7.16 | 2.7.16.x |
puppet / puppet | 2.7.17 | 2.7.17.x |
puppet / puppet | 2.7.18 | 2.7.18.x |
puppet / puppet_enterprise | 3.1.0 | 3.1.0.x |
puppetlabs / puppet | 2.7.0 | 2.7.0.x |
puppetlabs / puppet | 2.7.1 | 2.7.1.x |
puppetlabs / puppet | 2.7.19 | 2.7.19.x |
puppetlabs / puppet | 2.7.20 | 2.7.20.x |
puppetlabs / puppet | 2.7.20-rc1 | 2.7.20-rc1.x |
![]() |
2.7.0 | 2.7.21 |
![]() |
3.1.0 | 3.1.1 |