CVE-2025-5459
- EPSS 0.05%
- Veröffentlicht 26.06.2025 06:30:56
- Zuletzt bearbeitet 14.10.2025 17:00:33
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolve...
CVE-2023-5309
- EPSS 0.29%
- Veröffentlicht 07.11.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:41:30
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
CVE-2023-5255
- EPSS 0.14%
- Veröffentlicht 03.10.2023 18:15:10
- Zuletzt bearbeitet 20.11.2025 18:30:37
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
CVE-2023-2530
- EPSS 3.03%
- Veröffentlicht 07.06.2023 20:15:09
- Zuletzt bearbeitet 26.08.2025 15:15:39
A privilege escalation allowing remote code execution was discovered in the orchestration service.
CVE-2023-1894
- EPSS 0.05%
- Veröffentlicht 04.05.2023 23:15:08
- Zuletzt bearbeitet 29.01.2025 18:15:44
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
CVE-2021-27026
- EPSS 0.06%
- Veröffentlicht 18.11.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:57:12
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
CVE-2021-27025
- EPSS 0.2%
- Veröffentlicht 18.11.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:57:12
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
CVE-2021-27023
- EPSS 0.4%
- Veröffentlicht 18.11.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:57:11
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
CVE-2021-27022
- EPSS 0.34%
- Veröffentlicht 07.09.2021 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:57:11
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
CVE-2021-27020
- EPSS 0.5%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:57:11
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.