Show filters
134 Total Results
Displaying 81-90 of 134
Sort by:
Attacker Value
Unknown
CVE-2014-3251
Disclosure Date: August 12, 2014 (last updated October 05, 2023)
The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.
0
Attacker Value
Unknown
CVE-2014-3249
Disclosure Date: June 17, 2014 (last updated October 05, 2023)
Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.
0
Attacker Value
Unknown
CVE-2013-1398
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.
0
Attacker Value
Unknown
CVE-2013-4963
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.
0
Attacker Value
Unknown
CVE-2013-1399
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet Enterprise (PE) before 2.7.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2012-5158
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-0891
Disclosure Date: March 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.
0
Attacker Value
Unknown
CVE-2013-4971
Disclosure Date: March 09, 2014 (last updated October 05, 2023)
Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4966
Disclosure Date: March 09, 2014 (last updated October 05, 2023)
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.
0
Attacker Value
Unknown
CVE-2011-0528
Disclosure Date: February 17, 2014 (last updated October 05, 2023)
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.
0