Puppet

Puppet Enterprise

87 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Published 07.11.2023 19:15:12
  • Last modified 21.11.2024 08:41:30

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

  • EPSS 3.03%
  • Published 07.06.2023 20:15:09
  • Last modified 26.08.2025 15:15:39

A privilege escalation allowing remote code execution was discovered in the orchestration service.

  • EPSS 0.05%
  • Published 04.05.2023 23:15:08
  • Last modified 29.01.2025 18:15:44

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

  • EPSS 0.06%
  • Published 18.11.2021 15:15:09
  • Last modified 21.11.2024 05:57:12

A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

  • EPSS 0.17%
  • Published 18.11.2021 15:15:09
  • Last modified 21.11.2024 05:57:12

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

  • EPSS 0.27%
  • Published 18.11.2021 15:15:09
  • Last modified 21.11.2024 05:57:11

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

  • EPSS 0.34%
  • Published 07.09.2021 14:15:11
  • Last modified 21.11.2024 05:57:11

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).

  • EPSS 0.5%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:57:11

Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.

  • EPSS 0.2%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:57:11

PuppetDB logging included potentially sensitive system information.

  • EPSS 0.63%
  • Published 20.07.2021 11:15:11
  • Last modified 21.11.2024 05:57:11

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.