Show filters
134 Total Results
Displaying 1-10 of 134
Sort by:
Attacker Value
Unknown
CVE-2021-27017
Disclosure Date: February 07, 2025 (last updated February 08, 2025)
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
0
Attacker Value
Unknown
CVE-2024-9160
Disclosure Date: September 27, 2024 (last updated September 28, 2024)
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
0
Attacker Value
Unknown
CVE-2023-5309
Disclosure Date: November 07, 2023 (last updated November 16, 2023)
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
0
Attacker Value
Unknown
CVE-2023-5214
Disclosure Date: October 06, 2023 (last updated October 11, 2023)
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
0
Attacker Value
Unknown
CVE-2023-5255
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
0
Attacker Value
Unknown
CVE-2023-2530
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
A privilege escalation allowing remote code execution was discovered in the orchestration service.
0
Attacker Value
Unknown
CVE-2023-1894
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
0
Attacker Value
Unknown
CVE-2022-3276
Disclosure Date: October 07, 2022 (last updated October 08, 2023)
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
0
Attacker Value
Unknown
CVE-2022-3275
Disclosure Date: October 07, 2022 (last updated October 08, 2023)
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.
0
Attacker Value
Unknown
CVE-2022-0675
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.
0