CVE-2013-4966: Puppet Enterprise
Medium severity, CVSS 6.4. EPSS: 1.1% chance of exploitation in the next 30 days.
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.
Affected products
- Puppet Puppet Enterprise: up to and including 3.1.1; version 3.0.0 only; version 3.0.1 only; version 3.1.0 only
Published 2014-03-09. Last modified 2026-06-16.