CVE-2018-6513: Puppet
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet run. This was possible through the loading of shared libraries from untrusted paths.
Affected products
- Puppet Puppet: from 1.10.0, before 1.10.13 (fixed in 1.10.13); from 5.3.0, before 5.3.7 (fixed in 5.3.7); from 5.5.0, before 5.5.2 (fixed in 5.5.2)
- Puppet Puppet Enterprise: from 2016.4.0, before 2016.4.12 (fixed in 2016.4.12); from 2017.3.0, before 2017.3.7 (fixed in 2017.3.7); from 2018.1.0, before 2018.1.1 (fixed in 2018.1.1)
Published 2018-06-11. Last modified 2026-06-17.