Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Puppet Enterprise HIGH 8.8
CVE-2025-5459

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary …

Fix: 2023.8.4+
Fix from $1,950 2025-06-26
Puppet Enterprise CRITICAL 9.8
CVE-2023-5309

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

Fix: 2021.7.6 / 2023.5.0+
Fix from $2,300 2023-11-07
Bolt CRITICAL 9.8
CVE-2023-5214

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

Fix: 3.27.4+
Fix from $2,300 2023-10-06
Puppet Enterprise HIGH 7.5
CVE-2023-5255

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

Mitigation only
Fix from $1,950 2023-10-03
Puppet Enterprise CRITICAL 9.8
CVE-2023-2530

A privilege escalation allowing remote code execution was discovered in the orchestration service.

Fix: after 2021.7.3
Fix from $2,300 2023-06-07
Puppet Enterprise MEDIUM 5.3
CVE-2023-1894

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically c…

Mitigation only
Fix from $1,600 2023-05-04
Puppetlabs Mysql HIGH 8.8
CVE-2022-3276

Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if…

Fix: 13.0.0+
Fix from $1,950 2022-10-07
Firewall CRITICAL 9.8
CVE-2022-0675

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manif…

Fix: 3.4.0+
Fix from $2,300 2022-03-02
Continuous Delivery HIGH 8.1
CVE-2021-27024

A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet…

Fix: 4.10.0+
Fix from $1,950 2021-11-18
Puppet Enterprise HIGH 8.8
CVE-2021-27020

Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.

Fix: 2019.8.6+
Fix from $1,950 2021-08-30
Remediate HIGH 7.5
CVE-2021-27018

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate aut…

Fix: 2.0.1+
Fix from $1,950 2021-08-30
Puppet HIGH 8.8
CVE-2021-27021

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

Fix: 6.17.0 / 6.23.0+
Fix from $1,950 2021-07-20
Continuous Delivery MEDIUM 5.5
CVE-2020-7945

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not ha…

Mitigation only
Fix from $1,600 2020-09-18
Continuous Delivery HIGH 7.7
CVE-2020-7944

In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the …

Fix: 3.4.0+
Fix from $1,950 2020-03-26
Puppet Enterprise HIGH 7.5
CVE-2020-7943EPSS 8%

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things…

Fix: 5.2.15 / 5.3.13+
Fix from $1,950 2020-03-11
Puppet Enterprise HIGH 8.8
CVE-2015-5686

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would all…

Fix: 2015.2.0+
Fix from $1,950 2020-02-27
Puppet MEDIUM 6.5
CVE-2020-7942

Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised cert…

Fix: 5.5.19 / 6.13.0+
Fix from $1,600 2020-02-19
Puppet Server MEDIUM 5.4
CVE-2018-11751

Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6…

Fix: 6.4.0+
Fix from $1,600 2019-12-16
Puppet Enterprise CRITICAL 9.8
CVE-2019-10694

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…

Fix: 2018.1.9 / 2019.0.3+
Fix from $2,300 2019-12-12
Continuous Delivery MEDIUM 6.5
CVE-2019-10695

When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were expo…

Fix: 1.2.1+
Fix from $1,600 2019-12-12
Puppet Enterprise MEDIUM 6.1
CVE-2013-4968

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) co…

Fix: 3.0.1+
Fix from $1,600 2019-12-11
Chloride HIGH 7.5
CVE-2018-6517

Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts …

Fix: 0.3.0+
Fix from $1,950 2019-03-21
Discovery CRITICAL 9.8
CVE-2018-11747

Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will…

Fix: 1.4.0+
Fix from $2,300 2019-03-21
Cisco Ios MEDIUM 5.5
CVE-2018-11752

Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every r…

Fix: 0.4.0+
Fix from $1,600 2018-10-02
Device Manager HIGH 7.8
CVE-2018-11748

Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been…

Fix: 2.7.0+
Fix from $1,950 2018-10-02
Cisco Ios Module MEDIUM 6.5
CVE-2018-11750

Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisc…

Fix: 0.4.0+
Fix from $1,600 2018-10-02
Puppet Enterprise CRITICAL 9.8
CVE-2018-11749

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…

Fix: after 2018.1.3
Fix from $2,300 2018-08-24
Discovery CRITICAL 9.8
CVE-2018-11746

In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure c…

Fix: 1.2.0+
Fix from $2,300 2018-07-03
Puppet Enterprise Client Tools HIGH 7.8
CVE-2018-6516

On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16…

Fix: 16.4.6 / 17.3.6+
Fix from $1,950 2018-06-14
Pe Razor Server CRITICAL 9.8
CVE-2018-6512

The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …

Fix: 1.9.0.0 / 2018.1.1+
Fix from $2,300 2018-06-11