Loading...
Loading...
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
August 19, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-3567
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.