Show filters
89 Total Results
Displaying 1-10 of 89
Sort by:
Attacker Value
Unknown
CVE-2023-5309
Disclosure Date: November 07, 2023 (last updated November 16, 2023)
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
0
Attacker Value
Unknown
CVE-2023-2530
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
A privilege escalation allowing remote code execution was discovered in the orchestration service.
0
Attacker Value
Unknown
CVE-2023-1894
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
0
Attacker Value
Unknown
CVE-2021-27026
Disclosure Date: November 18, 2021 (last updated October 07, 2023)
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
0
Attacker Value
Unknown
CVE-2021-27025
Disclosure Date: November 18, 2021 (last updated October 07, 2023)
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
0
Attacker Value
Unknown
CVE-2021-27023
Disclosure Date: November 18, 2021 (last updated October 07, 2023)
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
0
Attacker Value
Unknown
CVE-2021-27022
Disclosure Date: September 07, 2021 (last updated November 08, 2023)
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
0
Attacker Value
Unknown
CVE-2021-27019
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
PuppetDB logging included potentially sensitive system information.
0
Attacker Value
Unknown
CVE-2021-27020
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
0
Attacker Value
Unknown
CVE-2021-27021
Disclosure Date: July 20, 2021 (last updated November 28, 2024)
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
0