Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Puppet HIGH 8.8
CVE-2018-6513

Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Age…

Fix: 1.10.13 / 5.3.7+
Fix from $1,950 2018-06-11
Puppet HIGH 7.8
CVE-2018-6514

In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a D…

Fix: 1.10.13 / 5.3.7+
Fix from $1,950 2018-06-11
Puppet HIGH 7.8
CVE-2018-6515

Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially craf…

Fix: 1.10.13 / 5.3.7+
Fix from $1,950 2018-06-11
Puppet Enterprise MEDIUM 5.4
CVE-2018-6510

A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Con…

Fix: 2017.3.6+
Fix from $1,600 2018-05-08
Puppet Enterprise MEDIUM 5.4
CVE-2018-6511

A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Con…

Fix: 2017.3.6+
Fix from $1,600 2018-05-08
Puppet Enterprise HIGH 8.0
CVE-2018-6508

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task…

Fix: after 2017.3.2
Fix from $1,950 2018-02-09
Puppet Enterprise HIGH 7.5
CVE-2017-2297

Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issu…

Fix: 2016.4.5+
Fix from $1,950 2018-02-01
Puppet Enterprise MEDIUM 6.5
CVE-2017-2296

In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RB…

Mitigation only
Fix from $1,600 2018-02-01
Puppetlabs Mysql CRITICAL 9.8
CVE-2015-7224

puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password …

Fix: after 3.6.0
Fix from $2,300 2017-12-21
Puppet Enterprise MEDIUM 6.8
CVE-2015-4100

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificat…

Fix: after 3.7.2
Fix from $1,600 2017-12-21
Puppet Enterprise MEDIUM 6.5
CVE-2015-8470

The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes i…

Fix: after 2015.2.3
Fix from $1,600 2017-12-11
Puppet Enterprise MEDIUM 6.1
CVE-2015-6502

Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script o…

Fix: 2015.2.1+
Fix from $1,600 2017-12-11
Puppet Agent CRITICAL 9.8
CVE-2016-5713

Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to …

Fix: 1.6.0+
Fix from $2,300 2017-12-06
Puppet Enterprise HIGH 7.2
CVE-2016-5714

Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect…

Fix: after 1.7.0
Fix from $1,950 2017-10-18
Puppetlabs Apache HIGH 7.5
CVE-2017-2299

Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_…

Mitigation only
Fix from $1,950 2017-09-15
Puppet Enterprise HIGH 8.8
CVE-2016-5716

The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution o…

Mitigation only
Fix from $1,950 2017-08-09
Puppet Enterprise HIGH 7.5
CVE-2017-2294

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.…

Fix: after 2016.4.3
Fix from $1,950 2017-07-05
Mcollective CRITICAL 9.0
CVE-2017-2292

Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution …

Fix: after 2.10.3
Fix from $2,300 2017-06-30
Mcollective Sshkey Security MEDIUM 6.5
CVE-2017-2298

The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compro…

Fix: after 0.5.0
Fix from $1,600 2017-06-30
Mcollective Puppet Agent HIGH 8.8
CVE-2017-2290

On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu…

Mitigation only
Fix from $1,950 2017-03-03
Marionette Collective CRITICAL 9.8
CVE-2016-2788

MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …

Fix: 3.8.6 / 2016.2.1+
Fix from $2,300 2017-02-13
Puppet Enterprise MEDIUM 5.3
CVE-2016-2787

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a…

Mitigation only
Fix from $1,600 2017-02-13
Puppet Enterprise MEDIUM 5.3
CVE-2016-9686

The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preve…

Fix: 2016.4.3+
Fix from $1,600 2017-02-08
Puppet Enterprise MEDIUM 6.1
CVE-2015-6501

Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and …

Fix: after 2015.2.0
Fix from $1,600 2017-01-12
Puppet Enterprise MEDIUM 6.1
CVE-2016-5715

Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitr…

Fix: after 2016.4.0
Fix from $1,600 2017-01-12
Puppet Agent CRITICAL 9.8
CVE-2016-2786

The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…

Mitigation only
Fix from $2,300 2016-06-10
Puppet CRITICAL 9.8
CVE-2016-2785

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass i…

Patch available
Fix from $2,300 2016-06-10
Puppet Enterprise HIGH 8.8
CVE-2015-7330

Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communicati…

Mitigation only
Fix from $1,950 2016-04-11
Stdlib MEDIUM 6.5
CVE-2015-1029

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g…

Mitigation only
Fix from $1,600 2015-01-16
Facter MEDIUM 6.2
CVE-2014-3248

Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0…

Fix: 1.3.4 / 2.5.2+
Fix from $1,600 2014-11-16