Перейти к содержимому
Noroxi

Записи puppetlabs

34 опубликованных записей вендора puppetlabs.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
82,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

34 записей
  • CVE-2013-1398
    34Наблюдать

    The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which a

    ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %

    puppet · puppet enterprise14 мар. 2014 г.

  • CVE-2013-1655
    31Наблюдать

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via v

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    puppet · puppet20 мар. 2013 г.

  • CVE-2013-3567
    31Наблюдать

    Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote atta

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    puppet · puppet19 авг. 2013 г.

  • CVE-2013-1653
    30Наблюдать

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening

    ВысокаяCVSS 7,1Эксплойта нетEPSS 5 %

    puppet · puppet20 мар. 2013 г.

  • CVE-2013-2274
    27Наблюдать

    Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppe

    СредняяCVSS 6,5Эксплойта нетEPSS 3 %

    puppet · puppet20 мар. 2013 г.

  • CVE-2013-1399
    27Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administrat

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    puppet · puppet enterprise14 мар. 2014 г.

  • CVE-2012-1053
    27Наблюдать

    The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    puppet · puppet29 мая 2012 г.

  • CVE-2015-7331
    26Наблюдать

    The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --s

    СредняяCVSS 6,6Эксплойта нетEPSS 1 %

    puppetlabs · mcollective-puppet-agent30 янв. 2017 г.

  • CVE-2011-3870
    25Наблюдать

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink att

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    puppet · puppet27 окт. 2011 г.

  • CVE-2011-3869
    25Наблюдать

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lo

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    puppet · puppet27 окт. 2011 г.

  • CVE-2014-3248
    24Наблюдать

    Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x b

    СредняяCVSS 6,2Эксплойта нетEPSS 1 %

    puppet · facter16 нояб. 2014 г.

  • CVE-2011-3871
    24Наблюдать

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local us

    СредняяCVSS 6,2Эксплойта нетEPSS 0 %

    puppet · puppet27 окт. 2011 г.

  • CVE-2013-1654
    21Наблюдать

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol be

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    puppet · puppet20 мар. 2013 г.

  • CVE-2016-2787
    21Наблюдать

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    puppet · puppet enterprise13 февр. 2017 г.

  • CVE-2013-1652
    20Наблюдать

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote a

    СредняяCVSS 4,9Эксплойта нетEPSS 2 %

    puppet · puppet20 мар. 2013 г.

  • CVE-2013-4761
    20Наблюдать

    Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.

    СредняяCVSS 5,1Эксплойта нетEPSS 2 %

    puppet · puppet20 авг. 2013 г.

  • CVE-2013-2716
    20Наблюдать

    Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upg

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    puppet · puppet enterprise10 апр. 2013 г.

  • CVE-2011-3848
    20Наблюдать

    Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Si

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    puppet · puppet27 окт. 2011 г.

  • CVE-2012-3867
    18Наблюдать

    lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not proper

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    puppet · puppet6 авг. 2012 г.

  • CVE-2013-2275
    17Наблюдать

    The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupp

    СредняяCVSS 4,0Эксплойта нетEPSS 3 %

    puppet · puppet20 мар. 2013 г.

  • CVE-2012-3864
    17Наблюдать

    Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files

    СредняяCVSS 4,0Эксплойта нетEPSS 2 %

    puppet · puppet6 авг. 2012 г.

  • CVE-2012-1054
    17Наблюдать

    Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a us

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    puppet · puppet29 мая 2012 г.

  • CVE-2014-3251
    17Наблюдать

    The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    puppet · puppet enterprise12 авг. 2014 г.

  • CVE-2012-5158
    16Наблюдать

    Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authentic

    СредняяCVSS 4,0Эксплойта нетEPSS 1 %

    puppet · puppet enterprise14 мар. 2014 г.

  • CVE-2012-3865
    15Наблюдать

    Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befo

    НизкаяCVSS 3,5Эксплойта нетEPSS 2 %

    puppet · puppet6 авг. 2012 г.