Product:

Puppet_enterprise

(Puppet)
Repositories https://github.com/puppetlabs/puppet
#Vulnerabilities 87
Date Id Summary Products Score Patch Annotated
2012-05-29 CVE-2012-1988 Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request. Ubuntu_linux, Debian_linux, Fedora, Puppet, Puppet_enterprise N/A
2023-11-07 CVE-2023-5309 Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations. Puppet_enterprise 9.8
2021-09-07 CVE-2021-27022 A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes). Puppet, Puppet_enterprise 4.9
2021-11-18 CVE-2021-27023 A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007 Fedora, Puppet_agent, Puppet_enterprise, Puppet_server 9.8
2021-11-18 CVE-2021-27025 A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. Fedora, Puppet, Puppet_agent, Puppet_enterprise 6.5
2023-05-04 CVE-2023-1894 A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. Puppet_enterprise, Puppet_server 5.3
2023-06-07 CVE-2023-2530 A privilege escalation allowing remote code execution was discovered in the orchestration service. Puppet_enterprise 9.8
2018-05-08 CVE-2018-6510 A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6. Puppet_enterprise 5.4
2018-05-08 CVE-2018-6511 A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6. Puppet_enterprise 5.4
2012-08-06 CVE-2012-3408 lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an agent by acquiring a previously used IP address. Puppet_enterprise, Puppet N/A