{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"versions ant\u00e9rieures \u00e0 Puppet Enterprise 2.8.3","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"versions ant\u00e9rieures \u00e0 Puppet 3.2.4","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"versions ant\u00e9rieures \u00e0 Puppet 2.7.23","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"Versions ant\u00e9rieures \u00e0 Puppet Enterprise 3.0.1","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2013-4073","url":"https://www.cve.org/CVERecord?id=CVE-2013-4073"},{"name":"CVE-2013-4968","url":"https://www.cve.org/CVERecord?id=CVE-2013-4968"},{"name":"CVE-2013-4956","url":"https://www.cve.org/CVERecord?id=CVE-2013-4956"},{"name":"CVE-2013-4761","url":"https://www.cve.org/CVERecord?id=CVE-2013-4761"},{"name":"CVE-2013-4962","url":"https://www.cve.org/CVERecord?id=CVE-2013-4962"},{"name":"CVE-2013-4955","url":"https://www.cve.org/CVERecord?id=CVE-2013-4955"},{"name":"CVE-2013-4762","url":"https://www.cve.org/CVERecord?id=CVE-2013-4762"},{"name":"CVE-2013-4964","url":"https://www.cve.org/CVERecord?id=CVE-2013-4964"},{"name":"CVE-2013-4959","url":"https://www.cve.org/CVERecord?id=CVE-2013-4959"},{"name":"CVE-2013-4967","url":"https://www.cve.org/CVERecord?id=CVE-2013-4967"},{"name":"CVE-2013-4958","url":"https://www.cve.org/CVERecord?id=CVE-2013-4958"},{"name":"CVE-2013-4961","url":"https://www.cve.org/CVERecord?id=CVE-2013-4961"},{"name":"CVE-2013-4963","url":"https://www.cve.org/CVERecord?id=CVE-2013-4963"}],"links":[{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4956 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4956"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4073 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4073"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4955 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4955"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4961 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4961"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4968 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4968"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4761 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4761"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4963 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4963"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4958 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4958"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4762 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4762"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4967 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4967"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4962 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4962"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4964 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4964"},{"title":"R\u00e9f\u00e9rence Puppet CVE-2013-4959 du 15 ao\u00fbt 2013","url":"http://puppetlabs.com/security/cve/CVE-2013-4959"}],"reference":"CERTA-2013-AVI-482","revisions":[{"description":"version initiale.","revision_date":"2013-08-19T00:00:00.000000"}],"risks":[{"description":"Ex\u00e9cution de code arbitraire \u00e0 distance"},{"description":"Injection de code indirecte \u00e0 distance"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans <span\nclass=\"textit\">Puppet</span>. Elles permettent \u00e0 un attaquant de\nprovoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une atteinte \u00e0 la\nconfidentialit\u00e9 des donn\u00e9es et une injection de code indirecte \u00e0\ndistance (XSS).\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans Puppet","vendor_advisories":[{"published_at":null,"title":"Bulletins de s\u00e9curit\u00e9 Puppet","url":"http://puppetlabs.com/security"}]}
