Show filters
119 Total Results
Displaying 1-10 of 119
Sort by:
Attacker Value
Unknown

CVE-2024-27294

Disclosure Date: February 29, 2024 (last updated March 01, 2024)
dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for files within the archive. dp-puppet version 1.2.7 will recreate installations if the owner or group of any file or directory within that installation does not match the requested owner or group
1
Attacker Value
Unknown

CVE-2021-27017

Disclosure Date: February 07, 2025 (last updated February 08, 2025)
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
0
Attacker Value
Unknown

CVE-2023-5309

Disclosure Date: November 07, 2023 (last updated November 16, 2023)
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
Attacker Value
Unknown

CVE-2023-5255

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
Attacker Value
Unknown

CVE-2023-2530

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
A privilege escalation allowing remote code execution was discovered in the orchestration service.
Attacker Value
Unknown

CVE-2023-1894

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
Attacker Value
Unknown

CVE-2022-25350

Disclosure Date: January 26, 2023 (last updated November 08, 2023)
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
Attacker Value
Unknown

CVE-2022-3276

Disclosure Date: October 07, 2022 (last updated October 08, 2023)
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
Attacker Value
Unknown

CVE-2022-3275

Disclosure Date: October 07, 2022 (last updated October 08, 2023)
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
Attacker Value
Unknown

CVE-2022-2394

Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.