Puppet records
128 published records for vendor puppet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls14
- CWE-20 Improper Input Validation12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-295 Improper Certificate Validation8
- CWE-287 Improper Authentication7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
The weakness classes this vendor ships most often: where to look.
CWEAll records
128 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2017-7529Proof of concept | Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultinf5 · nginx · CWE-190 | High7.5 | — | 62.6% | Jul 13, 2017 |
40Plan | CVE-2016-2785No exploit | Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers topuppet · puppet · CWE-284 | Critical9.8 | — | 2.9% | Jun 10, 2016 |
40Plan | CVE-2016-2788No exploit | MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relatepuppet · marionette collective · CWE-284 | Critical9.8 | — | 2.3% | Feb 13, 2017 |
40Plan | CVE-2022-3275No exploit | Puppetlabs-apt Command Injectionpuppet · puppetlabs-mysql · CWE-78 | Critical9.8 | — | 2.2% | Oct 7, 2022 |
40Plan | CVE-2014-0175No exploit | mcollective has a default password set at installpuppet · marionette collective · CWE-798 | Critical9.8 | — | 2.0% | Dec 13, 2019 |
40Plan | CVE-2016-5713No exploit | Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables thpuppet · puppet agent · CWE-94 | Critical9.8 | — | 2.0% | Dec 6, 2017 |
40Plan | CVE-2018-6512No exploit | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.puppet · pe-razor-server · CWE-94 | Critical9.8 | — | 1.9% | Jun 11, 2018 |
40Plan | CVE-2015-7224No exploit | puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a puppet · puppetlabs-mysql · CWE-287 | Critical9.8 | — | 1.7% | Dec 21, 2017 |
39Monitor | CVE-2016-2786No exploit | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server puppet · puppet agent · CWE-20 | Critical9.8 | — | 1.6% | Jun 10, 2016 |
39Monitor | CVE-2018-11746No exploit | Puppet Discovery can leak authentication informationpuppet · discovery · CWE-522 | Critical9.8 | — | 1.4% | Jul 3, 2018 |
39Monitor | CVE-2021-27023No exploit | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a difpuppet · puppet agent | Critical9.8 | — | 1.4% | Nov 18, 2021 |
39Monitor | CVE-2023-2530No exploit | A privilege escalation allowing remote code execution was discovered in the orchestration service.puppet · puppet enterprise · CWE-284 | Critical9.8 | — | 1.1% | Jun 7, 2023 |
39Monitor | CVE-2019-10694No exploit | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admipuppet · puppet enterprise · CWE-798 | Critical9.8 | — | 1.1% | Dec 11, 2019 |
39Monitor | CVE-2022-0675No exploit | Puppet Firewall Module May Leave Unmanaged Rulespuppet · firewall · CWE-1289 | Critical9.8 | — | 0.9% | Mar 2, 2022 |
39Monitor | CVE-2018-11749No exploit | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.puppet · puppet enterprise · CWE-319 | Critical9.8 | — | 0.8% | Aug 24, 2018 |
39Monitor | CVE-2018-11747No exploit | Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.puppet · discovery · CWE-295 | Critical9.8 | — | 0.7% | Mar 21, 2019 |
39Monitor | CVE-2023-5309No exploit | Broken Session Management in Puppet Enterprisepuppet · puppet enterprise · CWE-384 | Critical9.8 | — | 0.5% | Nov 7, 2023 |
39Monitor | CVE-2023-5214No exploit | CVE-2023-5214 - Privilege Escalation in Puppet Boltpuppet · bolt · CWE-269 | Critical9.8 | — | 0.4% | Oct 6, 2023 |
37Monitor | CVE-2013-1640No exploit | The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1puppet · puppet | Critical9.0 | — | 4.9% | Mar 20, 2013 |
37Monitor | CVE-2017-2292No exploit | Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code epuppet · mcollective · CWE-502 | Critical9.0 | — | 2.2% | Jun 30, 2017 |
36Monitor | CVE-2015-7330No exploit | Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet copuppet · puppet enterprise · CWE-254 | High8.8 | — | 2.1% | Apr 11, 2016 |
36Monitor | CVE-2016-5716No exploit | The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code expuppet · puppet enterprise · CWE-134 | High8.8 | — | 1.8% | Aug 9, 2017 |
35Monitor | CVE-2022-3276No exploit | Puppetlabs-mysql Command Injectionpuppet · puppetlabs-mysql · CWE-78 | High8.8 | — | 1.7% | Oct 7, 2022 |
35Monitor | CVE-2021-27021No exploit | A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL querypuppet · puppet · CWE-1027 | High8.8 | — | 1.3% | Jul 20, 2021 |
35Monitor | CVE-2017-2290No exploit | On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that willpuppet · mcollective-puppet-agent · CWE-732 | High8.8 | — | 1.2% | Mar 3, 2017 |
- CVE-2017-752949Plan
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultin
HighCVSS 7.5Proof of conceptEPSS 63%f5 · nginxJul 13, 2017
- CVE-2016-278540Plan
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to
CriticalCVSS 9.8No exploitEPSS 3%puppet · puppetJun 10, 2016
- CVE-2016-278840Plan
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relate
CriticalCVSS 9.8No exploitEPSS 2%puppet · marionette collectiveFeb 13, 2017
- CVE-2022-327540Plan
Puppetlabs-apt Command Injection
CriticalCVSS 9.8No exploitEPSS 2%puppet · puppetlabs-mysqlOct 7, 2022
- CVE-2014-017540Plan
mcollective has a default password set at install
CriticalCVSS 9.8No exploitEPSS 2%puppet · marionette collectiveDec 13, 2019
- CVE-2016-571340Plan
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables th
CriticalCVSS 9.8No exploitEPSS 2%puppet · puppet agentDec 6, 2017
- CVE-2018-651240Plan
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.
CriticalCVSS 9.8No exploitEPSS 2%puppet · pe-razor-serverJun 11, 2018
- CVE-2015-722440Plan
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a
CriticalCVSS 9.8No exploitEPSS 2%puppet · puppetlabs-mysqlDec 21, 2017
- CVE-2016-278639Monitor
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server
CriticalCVSS 9.8No exploitEPSS 2%puppet · puppet agentJun 10, 2016
- CVE-2018-1174639Monitor
Puppet Discovery can leak authentication information
CriticalCVSS 9.8No exploitEPSS 1%puppet · discoveryJul 3, 2018
- CVE-2021-2702339Monitor
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a dif
CriticalCVSS 9.8No exploitEPSS 1%puppet · puppet agentNov 18, 2021
- CVE-2023-253039Monitor
A privilege escalation allowing remote code execution was discovered in the orchestration service.
CriticalCVSS 9.8No exploitEPSS 1%puppet · puppet enterpriseJun 7, 2023
- CVE-2019-1069439Monitor
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admi
CriticalCVSS 9.8No exploitEPSS 1%puppet · puppet enterpriseDec 11, 2019
- CVE-2022-067539Monitor
Puppet Firewall Module May Leave Unmanaged Rules
CriticalCVSS 9.8No exploitEPSS 1%puppet · firewallMar 2, 2022
- CVE-2018-1174939Monitor
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.
CriticalCVSS 9.8No exploitEPSS 1%puppet · puppet enterpriseAug 24, 2018
- CVE-2018-1174739Monitor
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.
CriticalCVSS 9.8No exploitEPSS 1%puppet · discoveryMar 21, 2019
- CVE-2023-530939Monitor
Broken Session Management in Puppet Enterprise
CriticalCVSS 9.8No exploitEPSS 0%puppet · puppet enterpriseNov 7, 2023
- CVE-2023-521439Monitor
CVE-2023-5214 - Privilege Escalation in Puppet Bolt
CriticalCVSS 9.8No exploitEPSS 0%puppet · boltOct 6, 2023
- CVE-2013-164037Monitor
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1
CriticalCVSS 9.0No exploitEPSS 5%puppet · puppetMar 20, 2013
- CVE-2017-229237Monitor
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code e
CriticalCVSS 9.0No exploitEPSS 2%puppet · mcollectiveJun 30, 2017
- CVE-2015-733036Monitor
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet co
HighCVSS 8.8No exploitEPSS 2%puppet · puppet enterpriseApr 11, 2016
- CVE-2016-571636Monitor
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code ex
HighCVSS 8.8No exploitEPSS 2%puppet · puppet enterpriseAug 9, 2017
- CVE-2022-327635Monitor
Puppetlabs-mysql Command Injection
HighCVSS 8.8No exploitEPSS 2%puppet · puppetlabs-mysqlOct 7, 2022
- CVE-2021-2702135Monitor
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query
HighCVSS 8.8No exploitEPSS 1%puppet · puppetJul 20, 2021
- CVE-2017-229035Monitor
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will
HighCVSS 8.8No exploitEPSS 1%puppet · mcollective-puppet-agentMar 3, 2017