Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-5255 For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked. Puppet Enterprise Mitigation only Fix from $1,9502023-10-03 MEDIUM 5.3 CVE-2023-1894 A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically c… Puppet Enterprise Mitigation only Fix from $1,6002023-05-04 MEDIUM 5.5 CVE-2020-7945 Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not ha… Continuous Delivery Mitigation only Fix from $1,6002020-09-18 MEDIUM 6.5 CVE-2017-2296 In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RB… Puppet Enterprise Mitigation only Fix from $1,6002018-02-01 HIGH 7.5 CVE-2017-2299 Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_… Puppetlabs Apache Mitigation only Fix from $1,9502017-09-15 HIGH 8.8 CVE-2016-5716 The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution o… Puppet Enterprise Mitigation only Fix from $1,9502017-08-09 HIGH 8.8 CVE-2017-2290 On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu… Mcollective Puppet Agent Mitigation only Fix from $1,9502017-03-03 MEDIUM 5.3 CVE-2016-2787 The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a… Puppet Enterprise Mitigation only Fix from $1,6002017-02-13 CRITICAL 9.8 CVE-2016-2786 The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica… Puppet Agent Mitigation only Fix from $2,3002016-06-10 HIGH 8.8 CVE-2015-7330 Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communicati… Puppet Enterprise Mitigation only Fix from $1,9502016-04-11 MEDIUM 6.5 CVE-2015-1029 The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g… Stdlib Mitigation only Fix from $1,6002015-01-16 MEDIUM 5.0 CVE-2014-3249 Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes. Puppet Enterprise Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.5 CVE-2011-0528 Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the … Puppet Mitigation only Fix from $1,6002014-02-17 MEDIUM 5.1 CVE-2013-4761 Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allo… Puppet Mitigation only Fix from $1,6002013-08-20 HIGH 7.5 CVE-2013-1655 Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors re… Puppet Mitigation only Fix from $1,9502013-03-20 MEDIUM 6.5 CVE-2013-2274 Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master,… Puppet Mitigation only Fix from $1,6002013-03-20 MEDIUM 6.9 CVE-2012-1053 The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterpri… Puppet Mitigation only Fix from $1,6002012-05-29