Puppet

Puppet Enterprise

89 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 26.06.2025 06:30:56
  • Zuletzt bearbeitet 14.10.2025 17:00:33

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolve...

  • EPSS 0.29%
  • Veröffentlicht 07.11.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:41:30

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

  • EPSS 0.14%
  • Veröffentlicht 03.10.2023 18:15:10
  • Zuletzt bearbeitet 20.11.2025 18:30:37

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

  • EPSS 3.03%
  • Veröffentlicht 07.06.2023 20:15:09
  • Zuletzt bearbeitet 26.08.2025 15:15:39

A privilege escalation allowing remote code execution was discovered in the orchestration service.

  • EPSS 0.05%
  • Veröffentlicht 04.05.2023 23:15:08
  • Zuletzt bearbeitet 29.01.2025 18:15:44

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

  • EPSS 0.06%
  • Veröffentlicht 18.11.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:57:12

A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

  • EPSS 0.2%
  • Veröffentlicht 18.11.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:57:12

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

  • EPSS 0.4%
  • Veröffentlicht 18.11.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:57:11

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

  • EPSS 0.34%
  • Veröffentlicht 07.09.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:57:11

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).

  • EPSS 0.5%
  • Veröffentlicht 30.08.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:57:11

Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.