Skip to content
Noroxi

Puppet records

128 published records for vendor puppet.

All records

128 records
  • Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultin

    HighCVSS 7.5Proof of conceptEPSS 63%

    f5 · nginxJul 13, 2017

  • Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to

    CriticalCVSS 9.8No exploitEPSS 3%

    puppet · puppetJun 10, 2016

  • MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relate

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · marionette collectiveFeb 13, 2017

  • Puppetlabs-apt Command Injection

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · puppetlabs-mysqlOct 7, 2022

  • mcollective has a default password set at install

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · marionette collectiveDec 13, 2019

  • Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables th

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · puppet agentDec 6, 2017

  • The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · pe-razor-serverJun 11, 2018

  • puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · puppetlabs-mysqlDec 21, 2017

  • CVE-2016-2786
    39Monitor

    The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server

    CriticalCVSS 9.8No exploitEPSS 2%

    puppet · puppet agentJun 10, 2016

  • Puppet Discovery can leak authentication information

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · discoveryJul 3, 2018

  • A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a dif

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · puppet agentNov 18, 2021

  • CVE-2023-2530
    39Monitor

    A privilege escalation allowing remote code execution was discovered in the orchestration service.

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · puppet enterpriseJun 7, 2023

  • The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admi

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · puppet enterpriseDec 11, 2019

  • CVE-2022-0675
    39Monitor

    Puppet Firewall Module May Leave Unmanaged Rules

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · firewallMar 2, 2022

  • When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · puppet enterpriseAug 24, 2018

  • Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · discoveryMar 21, 2019

  • CVE-2023-5309
    39Monitor

    Broken Session Management in Puppet Enterprise

    CriticalCVSS 9.8No exploitEPSS 0%

    puppet · puppet enterpriseNov 7, 2023

  • CVE-2023-5214
    39Monitor

    CVE-2023-5214 - Privilege Escalation in Puppet Bolt

    CriticalCVSS 9.8No exploitEPSS 0%

    puppet · boltOct 6, 2023

  • CVE-2013-1640
    37Monitor

    The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1

    CriticalCVSS 9.0No exploitEPSS 5%

    puppet · puppetMar 20, 2013

  • CVE-2017-2292
    37Monitor

    Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code e

    CriticalCVSS 9.0No exploitEPSS 2%

    puppet · mcollectiveJun 30, 2017

  • CVE-2015-7330
    36Monitor

    Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet co

    HighCVSS 8.8No exploitEPSS 2%

    puppet · puppet enterpriseApr 11, 2016

  • CVE-2016-5716
    36Monitor

    The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code ex

    HighCVSS 8.8No exploitEPSS 2%

    puppet · puppet enterpriseAug 9, 2017

  • CVE-2022-3276
    35Monitor

    Puppetlabs-mysql Command Injection

    HighCVSS 8.8No exploitEPSS 2%

    puppet · puppetlabs-mysqlOct 7, 2022

  • A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query

    HighCVSS 8.8No exploitEPSS 1%

    puppet · puppetJul 20, 2021

  • CVE-2017-2290
    35Monitor

    On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will

    HighCVSS 8.8No exploitEPSS 1%

    puppet · mcollective-puppet-agentMar 3, 2017