CVE-2023-5255
- EPSS 0.14%
- Published 03.10.2023 18:15:10
- Last modified 21.11.2024 08:41:23
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
CVE-2021-27026
- EPSS 0.06%
- Published 18.11.2021 15:15:09
- Last modified 21.11.2024 05:57:12
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
CVE-2021-27025
- EPSS 0.17%
- Published 18.11.2021 15:15:09
- Last modified 21.11.2024 05:57:12
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
CVE-2021-27022
- EPSS 0.34%
- Published 07.09.2021 14:15:11
- Last modified 21.11.2024 05:57:11
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
CVE-2021-27021
- EPSS 0.63%
- Published 20.07.2021 11:15:11
- Last modified 21.11.2024 05:57:11
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
CVE-2020-7942
- EPSS 0.12%
- Published 19.02.2020 21:15:11
- Last modified 21.11.2024 05:38:03
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `...
CVE-2018-6515
- EPSS 0.22%
- Published 11.06.2018 20:29:00
- Last modified 21.11.2024 04:10:48
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalati...
CVE-2018-6514
- EPSS 0.22%
- Published 11.06.2018 20:29:00
- Last modified 21.11.2024 04:10:48
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.
CVE-2018-6513
- EPSS 0.37%
- Published 11.06.2018 20:29:00
- Last modified 21.11.2024 04:10:48
Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2,...
CVE-2017-10689
- EPSS 0.09%
- Published 09.02.2018 20:29:00
- Last modified 21.11.2024 03:06:18
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.