Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Puppet Enterprise MEDIUM 5.0
CVE-2014-3249

Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.

Mitigation only
Fix from $1,600 2014-06-17
Puppet Enterprise MEDIUM 6.8
CVE-2013-4963

Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication…

Fix: after 3.0.0
Fix from $1,600 2014-03-14
Puppet Enterprise HIGH 8.5
CVE-2013-1398

The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows rem…

Fix: after 2.7.0
Fix from $1,950 2014-03-14
Puppet Enterprise MEDIUM 6.8
CVE-2013-1399

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration compo…

Fix: after 2.7.0
Fix from $1,600 2014-03-14
Puppet Enterprise MEDIUM 6.4
CVE-2013-4966

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attack…

Fix: after 3.1.1
Fix from $1,600 2014-03-09
Puppet Enterprise MEDIUM 5.0
CVE-2013-4971

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive …

Fix: after 3.1.1
Fix from $1,600 2014-03-09
Puppet MEDIUM 5.5
CVE-2011-0528

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the …

Mitigation only
Fix from $1,600 2014-02-17
Puppet Enterprise MEDIUM 6.8
CVE-2013-4957

The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type.

Fix: after 3.0.0
Fix from $1,600 2013-10-25
Puppet Enterprise MEDIUM 5.0
CVE-2013-4965

Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remot…

Fix: after 3.0.1
Fix from $1,600 2013-10-25
Puppet Enterprise MEDIUM 6.9
CVE-2013-4958

Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended wor…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.8
CVE-2013-4762

Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.8
CVE-2013-4955

Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect users to arbitrary web sites and …

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.8
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwor…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet MEDIUM 5.1
CVE-2013-4761

Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allo…

Mitigation only
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.0
CVE-2013-4961

Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows …

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.0
CVE-2013-4964

Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.0
CVE-2013-4967

Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a consol…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.0
CVE-2013-2716

Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading fr…

Fix: after 2.7.2
Fix from $1,600 2013-04-10
Puppet HIGH 7.5
CVE-2013-1655

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors re…

Mitigation only
Fix from $1,950 2013-03-20
Puppet MEDIUM 6.5
CVE-2013-2274

Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master,…

Mitigation only
Fix from $1,600 2013-03-20
Puppet MEDIUM 6.9
CVE-2012-1053

The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterpri…

Mitigation only
Fix from $1,600 2012-05-29
Puppet MEDIUM 6.3
CVE-2011-3869

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

Patch available
Fix from $1,600 2011-10-27
Puppet MEDIUM 6.3
CVE-2011-3870

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on th…

Patch available
Fix from $1,600 2011-10-27
Puppet MEDIUM 6.2
CVE-2011-3871

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to ru…

Patch available
Fix from $1,600 2011-10-27
Puppet MEDIUM 5.0
CVE-2011-3848

Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Req…

Patch available
Fix from $1,600 2011-10-27