Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2018-6513
Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Age…
Puppet
1.10.13 / 5.3.7+
HIGH 7.8
CVE-2018-6514
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a D…
Puppet
1.10.13 / 5.3.7+
HIGH 7.8
CVE-2018-6515
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially craf…
Puppet
1.10.13 / 5.3.7+
MEDIUM 5.4
CVE-2018-6510
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Con…
Puppet Enterprise
2017.3.6+
MEDIUM 5.4
CVE-2018-6511
A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Con…
Puppet Enterprise
2017.3.6+
HIGH 8.0
CVE-2018-6508
Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task…
Puppet Enterprise
after 2017.3.2
HIGH 7.5
CVE-2017-2297
Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issu…
Puppet Enterprise
2016.4.5+
MEDIUM 6.5
CVE-2017-2296
In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RB…
Puppet Enterprise
Mitigation only
CRITICAL 9.8
CVE-2015-7224
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password …
Puppetlabs Mysql
after 3.6.0
MEDIUM 6.8
CVE-2015-4100
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificat…
Puppet Enterprise
after 3.7.2
MEDIUM 6.5
CVE-2015-8470
The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes i…
Puppet Enterprise
after 2015.2.3
MEDIUM 6.1
CVE-2015-6502
Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script o…
Puppet Enterprise
2015.2.1+
CRITICAL 9.8
CVE-2016-5713
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to …
Puppet Agent
1.6.0+
HIGH 7.2
CVE-2016-5714
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect…
Puppet Enterprise
after 1.7.0
HIGH 7.5
CVE-2017-2299
Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_…
Puppetlabs Apache
Mitigation only
HIGH 8.8
CVE-2016-5716
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution o…
Puppet Enterprise
Mitigation only
HIGH 7.5
CVE-2017-2294
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.…
Puppet Enterprise
after 2016.4.3
CRITICAL 9.0
CVE-2017-2292
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution …
Mcollective
after 2.10.3
MEDIUM 6.5
CVE-2017-2298
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compro…
Mcollective Sshkey Security
after 0.5.0
HIGH 8.8
CVE-2017-2290
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu…
Mcollective Puppet Agent
Mitigation only
CRITICAL 9.8
CVE-2016-2788
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …
Marionette Collective
3.8.6 / 2016.2.1+
MEDIUM 5.3
CVE-2016-2787
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a…
Puppet Enterprise
Mitigation only
MEDIUM 5.3
CVE-2016-9686
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preve…
Puppet Enterprise
2016.4.3+
MEDIUM 6.1
CVE-2015-6501
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and …
Puppet Enterprise
after 2015.2.0
MEDIUM 6.1
CVE-2016-5715
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitr…
Puppet Enterprise
after 2016.4.0
CRITICAL 9.8
CVE-2016-2786
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…
Puppet Agent
Mitigation only
CRITICAL 9.8
CVE-2016-2785
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass i…
Puppet
Patch available
HIGH 8.8
CVE-2015-7330
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communicati…
Puppet Enterprise
Mitigation only
MEDIUM 6.5
CVE-2015-1029
The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g…
Stdlib
Mitigation only
MEDIUM 6.2
CVE-2014-3248
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0…
Facter
1.3.4 / 2.5.2+