CVE-2018-6513
Dashboard / Vulnerabilities / CVE-2018-6513
CVE-2018-6513
Published: 11 Jun 2018Last Modified: 8 Jul 2026
Summary:
Details: Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet run. This was possible through the loading of shared libraries from untrusted paths.
References: https://puppet.com/security/cve/CVE-2018-6513
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 384311c359e43ac56cbb937fca9aba82068fd2d6
Affected versions
5.3.6
5.3.5
5.3.4
5.3.3
5.3.1
5.3.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
