CVE-2013-3567: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only
  • Novell Suse Linux Enterprise Desktop: version 11 only; version 11.0 only
  • Novell Suse Linux Enterprise Server: version 11.0 only
  • Puppet Puppet: version 2.7.2 only; version 2.7.10 only; version 2.7.11 only; version 2.7.12 only; version 2.7.13 only; version 2.7.14 only; …
  • Puppet Puppet Enterprise: up to and including 2.8.1; version 1.0 only; version 1.1 only; version 1.2.0 only; version 2.0.0 only; version 2.5.1 only; …
  • Puppetlabs Puppet: version 2.7.0 only; version 2.7.1 only; version 2.7.19 only; version 2.7.20 only; version 3.2.0 only; version 1.0.0 only; …

Published 2013-08-19. Last modified 2026-06-16.