Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-6513 Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Age… Puppet 1.10.13 / 5.3.7+ Fix from $1,9502018-06-11 HIGH 7.8 CVE-2018-6514 In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a D… Puppet 1.10.13 / 5.3.7+ Fix from $1,9502018-06-11 HIGH 7.8 CVE-2018-6515 Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially craf… Puppet 1.10.13 / 5.3.7+ Fix from $1,9502018-06-11 MEDIUM 5.4 CVE-2018-6510 A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Con… Puppet Enterprise 2017.3.6+ Fix from $1,6002018-05-08 MEDIUM 5.4 CVE-2018-6511 A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Con… Puppet Enterprise 2017.3.6+ Fix from $1,6002018-05-08 HIGH 8.0 CVE-2018-6508 Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task… Puppet Enterprise after 2017.3.2 Fix from $1,9502018-02-09 HIGH 7.5 CVE-2017-2297 Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issu… Puppet Enterprise 2016.4.5+ Fix from $1,9502018-02-01 MEDIUM 6.5 CVE-2017-2296 In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RB… Puppet Enterprise Mitigation only Fix from $1,6002018-02-01 CRITICAL 9.8 CVE-2015-7224 puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password … Puppetlabs Mysql after 3.6.0 Fix from $2,3002017-12-21 MEDIUM 6.8 CVE-2015-4100 Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificat… Puppet Enterprise after 3.7.2 Fix from $1,6002017-12-21 MEDIUM 6.5 CVE-2015-8470 The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes i… Puppet Enterprise after 2015.2.3 Fix from $1,6002017-12-11 MEDIUM 6.1 CVE-2015-6502 Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script o… Puppet Enterprise 2015.2.1+ Fix from $1,6002017-12-11 CRITICAL 9.8 CVE-2016-5713 Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to … Puppet Agent 1.6.0+ Fix from $2,3002017-12-06 HIGH 7.2 CVE-2016-5714 Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect… Puppet Enterprise after 1.7.0 Fix from $1,9502017-10-18 HIGH 7.5 CVE-2017-2299 Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_… Puppetlabs Apache Mitigation only Fix from $1,9502017-09-15 HIGH 8.8 CVE-2016-5716 The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution o… Puppet Enterprise Mitigation only Fix from $1,9502017-08-09 HIGH 7.5 CVE-2017-2294 Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.… Puppet Enterprise after 2016.4.3 Fix from $1,9502017-07-05 CRITICAL 9.0 CVE-2017-2292 Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution … Mcollective after 2.10.3 Fix from $2,3002017-06-30 MEDIUM 6.5 CVE-2017-2298 The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compro… Mcollective Sshkey Security after 0.5.0 Fix from $1,6002017-06-30 HIGH 8.8 CVE-2017-2290 On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu… Mcollective Puppet Agent Mitigation only Fix from $1,9502017-03-03 CRITICAL 9.8 CVE-2016-2788 MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the … Marionette Collective 3.8.6 / 2016.2.1+ Fix from $2,3002017-02-13 MEDIUM 5.3 CVE-2016-2787 The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a… Puppet Enterprise Mitigation only Fix from $1,6002017-02-13 MEDIUM 5.3 CVE-2016-9686 The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preve… Puppet Enterprise 2016.4.3+ Fix from $1,6002017-02-08 MEDIUM 6.1 CVE-2015-6501 Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and … Puppet Enterprise after 2015.2.0 Fix from $1,6002017-01-12 MEDIUM 6.1 CVE-2016-5715 Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitr… Puppet Enterprise after 2016.4.0 Fix from $1,6002017-01-12 CRITICAL 9.8 CVE-2016-2786 The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica… Puppet Agent Mitigation only Fix from $2,3002016-06-10 CRITICAL 9.8 CVE-2016-2785 Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass i… Puppet Patch available Fix from $2,3002016-06-10 HIGH 8.8 CVE-2015-7330 Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communicati… Puppet Enterprise Mitigation only Fix from $1,9502016-04-11 MEDIUM 6.5 CVE-2015-1029 The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g… Stdlib Mitigation only Fix from $1,6002015-01-16 MEDIUM 6.2 CVE-2014-3248 Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0… Facter 1.3.4 / 2.5.2+ Fix from $1,6002014-11-16