CVE-2013-1640: Canonical Ubuntu Linux
High severity, CVSS 9.0. EPSS: 4.9% chance of exploitation in the next 30 days.
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
Affected products
- Canonical Ubuntu Linux: version 11.10 only; version 12.04 only; version 12.10 only
- Puppet Puppet: before 2.6.18 (fixed in 2.6.18); from 2.7.0, before 2.7.21 (fixed in 2.7.21); version 3.1.0 only
- Puppet Puppet Enterprise: before 1.2.7 (fixed in 1.2.7); version 2.7.0 only; version 2.7.1 only
Published 2013-03-20. Last modified 2026-06-16.