Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Puppet Enterprise HIGH 7.5
CVE-2023-5255

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

Mitigation only
Fix from $1,950 2023-10-03
Puppet Enterprise MEDIUM 5.3
CVE-2023-1894

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically c…

Mitigation only
Fix from $1,600 2023-05-04
Continuous Delivery MEDIUM 5.5
CVE-2020-7945

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not ha…

Mitigation only
Fix from $1,600 2020-09-18
Puppet Enterprise MEDIUM 6.5
CVE-2017-2296

In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RB…

Mitigation only
Fix from $1,600 2018-02-01
Puppetlabs Apache HIGH 7.5
CVE-2017-2299

Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_…

Mitigation only
Fix from $1,950 2017-09-15
Puppet Enterprise HIGH 8.8
CVE-2016-5716

The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution o…

Mitigation only
Fix from $1,950 2017-08-09
Mcollective Puppet Agent HIGH 8.8
CVE-2017-2290

On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu…

Mitigation only
Fix from $1,950 2017-03-03
Puppet Enterprise MEDIUM 5.3
CVE-2016-2787

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a…

Mitigation only
Fix from $1,600 2017-02-13
Puppet Agent CRITICAL 9.8
CVE-2016-2786

The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…

Mitigation only
Fix from $2,300 2016-06-10
Puppet Enterprise HIGH 8.8
CVE-2015-7330

Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communicati…

Mitigation only
Fix from $1,950 2016-04-11
Stdlib MEDIUM 6.5
CVE-2015-1029

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g…

Mitigation only
Fix from $1,600 2015-01-16
Puppet Enterprise MEDIUM 5.0
CVE-2014-3249

Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.

Mitigation only
Fix from $1,600 2014-06-17
Puppet MEDIUM 5.5
CVE-2011-0528

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the …

Mitigation only
Fix from $1,600 2014-02-17
Puppet MEDIUM 5.1
CVE-2013-4761

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allo…

Mitigation only
Fix from $1,600 2013-08-20
Puppet HIGH 7.5
CVE-2013-1655

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors re…

Mitigation only
Fix from $1,950 2013-03-20
Puppet MEDIUM 6.5
CVE-2013-2274

Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master,…

Mitigation only
Fix from $1,600 2013-03-20
Puppet MEDIUM 6.9
CVE-2012-1053

The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterpri…

Mitigation only
Fix from $1,600 2012-05-29