[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-849 ---- puppet3

ID: oval:org.secpod.oval:def:1600721Date: (C)2017-06-27   (M)2023-04-17
Class: PATCHFamily: unix




Unsafe YAML deserialization:Versions of Puppet prior to 4.10.1 will deserialize data off the wire with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML

Platform:
Amazon Linux AMI
Product:
puppet3
Reference:
ALAS-2017-849
CVE-2017-2295
CVE    1
CVE-2017-2295
CPE    2
cpe:/o:amazon:linux
cpe:/a:puppetlabs:puppet3

© SecPod Technologies