CVE-2023-5309
- EPSS 0.29%
- Published 07.11.2023 19:15:12
- Last modified 21.11.2024 08:41:30
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
CVE-2023-2530
- EPSS 3.03%
- Published 07.06.2023 20:15:09
- Last modified 26.08.2025 15:15:39
A privilege escalation allowing remote code execution was discovered in the orchestration service.
CVE-2023-1894
- EPSS 0.05%
- Published 04.05.2023 23:15:08
- Last modified 29.01.2025 18:15:44
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
CVE-2021-27026
- EPSS 0.06%
- Published 18.11.2021 15:15:09
- Last modified 21.11.2024 05:57:12
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
CVE-2021-27025
- EPSS 0.17%
- Published 18.11.2021 15:15:09
- Last modified 21.11.2024 05:57:12
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
CVE-2021-27023
- EPSS 0.27%
- Published 18.11.2021 15:15:09
- Last modified 21.11.2024 05:57:11
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
CVE-2021-27022
- EPSS 0.34%
- Published 07.09.2021 14:15:11
- Last modified 21.11.2024 05:57:11
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
CVE-2021-27020
- EPSS 0.5%
- Published 30.08.2021 18:15:08
- Last modified 21.11.2024 05:57:11
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
CVE-2021-27019
- EPSS 0.2%
- Published 30.08.2021 18:15:08
- Last modified 21.11.2024 05:57:11
PuppetDB logging included potentially sensitive system information.
CVE-2021-27021
- EPSS 0.63%
- Published 20.07.2021 11:15:11
- Last modified 21.11.2024 05:57:11
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.