Skip to content
Noroxi

puppetlabs records

34 published records for vendor puppetlabs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
82.4%
Median publish → KEV
No record has entered KEV

All records

34 records
  • CVE-2013-1398
    34Monitor

    The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which a

    HighCVSS 8.5No exploitEPSS 2%

    puppet · puppet enterpriseMar 14, 2014

  • CVE-2013-1655
    31Monitor

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via v

    HighCVSS 7.5No exploitEPSS 5%

    puppet · puppetMar 20, 2013

  • CVE-2013-3567
    31Monitor

    Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote atta

    HighCVSS 7.5No exploitEPSS 3%

    puppet · puppetAug 19, 2013

  • CVE-2013-1653
    30Monitor

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening

    HighCVSS 7.1No exploitEPSS 5%

    puppet · puppetMar 20, 2013

  • CVE-2013-2274
    27Monitor

    Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppe

    MediumCVSS 6.5No exploitEPSS 3%

    puppet · puppetMar 20, 2013

  • CVE-2013-1399
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administrat

    MediumCVSS 6.8No exploitEPSS 1%

    puppet · puppet enterpriseMar 14, 2014

  • CVE-2012-1053
    27Monitor

    The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet

    MediumCVSS 6.9No exploitEPSS 0%

    puppet · puppetMay 29, 2012

  • CVE-2015-7331
    26Monitor

    The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --s

    MediumCVSS 6.6No exploitEPSS 1%

    puppetlabs · mcollective-puppet-agentJan 30, 2017

  • CVE-2011-3870
    25Monitor

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink att

    MediumCVSS 6.3No exploitEPSS 0%

    puppet · puppetOct 27, 2011

  • CVE-2011-3869
    25Monitor

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lo

    MediumCVSS 6.3No exploitEPSS 0%

    puppet · puppetOct 27, 2011

  • CVE-2014-3248
    24Monitor

    Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x b

    MediumCVSS 6.2No exploitEPSS 1%

    puppet · facterNov 16, 2014

  • CVE-2011-3871
    24Monitor

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local us

    MediumCVSS 6.2No exploitEPSS 0%

    puppet · puppetOct 27, 2011

  • CVE-2013-1654
    21Monitor

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol be

    MediumCVSS 5.0No exploitEPSS 3%

    puppet · puppetMar 20, 2013

  • CVE-2016-2787
    21Monitor

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node

    MediumCVSS 5.3No exploitEPSS 1%

    puppet · puppet enterpriseFeb 13, 2017

  • CVE-2013-1652
    20Monitor

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote a

    MediumCVSS 4.9No exploitEPSS 2%

    puppet · puppetMar 20, 2013

  • CVE-2013-4761
    20Monitor

    Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.

    MediumCVSS 5.1No exploitEPSS 2%

    puppet · puppetAug 20, 2013

  • CVE-2013-2716
    20Monitor

    Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upg

    MediumCVSS 5.0No exploitEPSS 1%

    puppet · puppet enterpriseApr 10, 2013

  • CVE-2011-3848
    20Monitor

    Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Si

    MediumCVSS 5.0No exploitEPSS 1%

    puppet · puppetOct 27, 2011

  • CVE-2012-3867
    18Monitor

    lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not proper

    MediumCVSS 4.3No exploitEPSS 2%

    puppet · puppetAug 6, 2012

  • CVE-2013-2275
    17Monitor

    The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupp

    MediumCVSS 4.0No exploitEPSS 3%

    puppet · puppetMar 20, 2013

  • CVE-2012-3864
    17Monitor

    Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files

    MediumCVSS 4.0No exploitEPSS 2%

    puppet · puppetAug 6, 2012

  • CVE-2012-1054
    17Monitor

    Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a us

    MediumCVSS 4.4No exploitEPSS 0%

    puppet · puppetMay 29, 2012

  • CVE-2014-3251
    17Monitor

    The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new

    MediumCVSS 4.4No exploitEPSS 0%

    puppet · puppet enterpriseAug 12, 2014

  • CVE-2012-5158
    16Monitor

    Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authentic

    MediumCVSS 4.0No exploitEPSS 1%

    puppet · puppet enterpriseMar 14, 2014

  • CVE-2012-3865
    15Monitor

    Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befo

    LowCVSS 3.5No exploitEPSS 2%

    puppet · puppetAug 6, 2012