Show filters
134 Total Results
Displaying 81-90 of 134
Sort by:
Attacker Value
Unknown

CVE-2014-3251

Disclosure Date: August 12, 2014 (last updated October 05, 2023)
The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.
0
Attacker Value
Unknown

CVE-2014-3249

Disclosure Date: June 17, 2014 (last updated October 05, 2023)
Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.
0
Attacker Value
Unknown

CVE-2013-1398

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.
0
Attacker Value
Unknown

CVE-2013-4963

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.
0
Attacker Value
Unknown

CVE-2013-1399

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet Enterprise (PE) before 2.7.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-5158

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0891

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.
0
Attacker Value
Unknown

CVE-2013-4971

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4966

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.
0
Attacker Value
Unknown

CVE-2011-0528

Disclosure Date: February 17, 2014 (last updated October 05, 2023)
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
0