puppetlabs records
34 published records for vendor puppetlabs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 82.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-20 Improper Input Validation3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-287 Improper Authentication2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-310 Cryptographic Issues2
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2013-1398No exploit | The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which apuppet · puppet enterprise · CWE-310 | High8.5 | — | 1.5% | Mar 14, 2014 |
31Monitor | CVE-2013-1655No exploit | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vpuppet · puppet · CWE-20 | High7.5 | — | 4.6% | Mar 20, 2013 |
31Monitor | CVE-2013-3567No exploit | Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attapuppet · puppet · CWE-20 | High7.5 | — | 3.4% | Aug 19, 2013 |
30Monitor | CVE-2013-1653No exploit | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listeningpuppet · puppet | High7.1 | — | 5.4% | Mar 20, 2013 |
27Monitor | CVE-2013-2274No exploit | Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppepuppet · puppet | Medium6.5 | — | 2.9% | Mar 20, 2013 |
27Monitor | CVE-2013-1399No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administratpuppet · puppet enterprise · CWE-352 | Medium6.8 | — | 0.6% | Mar 14, 2014 |
27Monitor | CVE-2012-1053No exploit | The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppetpuppet · puppet · CWE-264 | Medium6.9 | — | 0.4% | May 29, 2012 |
26Monitor | CVE-2015-7331No exploit | The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --spuppetlabs · mcollective-puppet-agent · CWE-254 | Medium6.6 | — | 1.2% | Jan 30, 2017 |
25Monitor | CVE-2011-3870No exploit | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attpuppet · puppet · CWE-59 | Medium6.3 | — | 0.4% | Oct 27, 2011 |
25Monitor | CVE-2011-3869No exploit | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lopuppet · puppet · CWE-59 | Medium6.3 | — | 0.3% | Oct 27, 2011 |
24Monitor | CVE-2014-3248No exploit | Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x bpuppet · facter · CWE-17 | Medium6.2 | — | 0.5% | Nov 16, 2014 |
24Monitor | CVE-2011-3871No exploit | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local uspuppet · puppet · CWE-264 | Medium6.2 | — | 0.3% | Oct 27, 2011 |
21Monitor | CVE-2013-1654No exploit | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol bepuppet · puppet | Medium5.0 | — | 2.9% | Mar 20, 2013 |
21Monitor | CVE-2016-2787No exploit | The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker nodepuppet · puppet enterprise · CWE-284 | Medium5.3 | — | 0.6% | Feb 13, 2017 |
20Monitor | CVE-2013-1652No exploit | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote apuppet · puppet · CWE-264 | Medium4.9 | — | 1.9% | Mar 20, 2013 |
20Monitor | CVE-2013-4761No exploit | Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.puppet · puppet | Medium5.1 | — | 1.6% | Aug 20, 2013 |
20Monitor | CVE-2013-2716No exploit | Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgpuppet · puppet enterprise · CWE-310 | Medium5.0 | — | 1.3% | Apr 10, 2013 |
20Monitor | CVE-2011-3848No exploit | Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Sipuppet · puppet · CWE-22 | Medium5.0 | — | 1.1% | Oct 27, 2011 |
18Monitor | CVE-2012-3867No exploit | lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properpuppet · puppet · CWE-264 | Medium4.3 | — | 2.5% | Aug 6, 2012 |
17Monitor | CVE-2013-2275No exploit | The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupppuppet · puppet | Medium4.0 | — | 2.9% | Mar 20, 2013 |
17Monitor | CVE-2012-3864No exploit | Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files puppet · puppet · CWE-200 | Medium4.0 | — | 1.9% | Aug 6, 2012 |
17Monitor | CVE-2012-1054No exploit | Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a uspuppet · puppet · CWE-264 | Medium4.4 | — | 0.4% | May 29, 2012 |
17Monitor | CVE-2014-3251No exploit | The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new puppet · puppet enterprise · CWE-362 | Medium4.4 | — | 0.2% | Aug 12, 2014 |
16Monitor | CVE-2012-5158No exploit | Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticpuppet · puppet enterprise · CWE-287 | Medium4.0 | — | 0.8% | Mar 14, 2014 |
15Monitor | CVE-2012-3865No exploit | Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befopuppet · puppet · CWE-22 | Low3.5 | — | 1.9% | Aug 6, 2012 |
- CVE-2013-139834Monitor
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which a
HighCVSS 8.5No exploitEPSS 2%puppet · puppet enterpriseMar 14, 2014
- CVE-2013-165531Monitor
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via v
HighCVSS 7.5No exploitEPSS 5%puppet · puppetMar 20, 2013
- CVE-2013-356731Monitor
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote atta
HighCVSS 7.5No exploitEPSS 3%puppet · puppetAug 19, 2013
- CVE-2013-165330Monitor
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening
HighCVSS 7.1No exploitEPSS 5%puppet · puppetMar 20, 2013
- CVE-2013-227427Monitor
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppe
MediumCVSS 6.5No exploitEPSS 3%puppet · puppetMar 20, 2013
- CVE-2013-139927Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administrat
MediumCVSS 6.8No exploitEPSS 1%puppet · puppet enterpriseMar 14, 2014
- CVE-2012-105327Monitor
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet
MediumCVSS 6.9No exploitEPSS 0%puppet · puppetMay 29, 2012
- CVE-2015-733126Monitor
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --s
MediumCVSS 6.6No exploitEPSS 1%puppetlabs · mcollective-puppet-agentJan 30, 2017
- CVE-2011-387025Monitor
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink att
MediumCVSS 6.3No exploitEPSS 0%puppet · puppetOct 27, 2011
- CVE-2011-386925Monitor
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lo
MediumCVSS 6.3No exploitEPSS 0%puppet · puppetOct 27, 2011
- CVE-2014-324824Monitor
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x b
MediumCVSS 6.2No exploitEPSS 1%puppet · facterNov 16, 2014
- CVE-2011-387124Monitor
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local us
MediumCVSS 6.2No exploitEPSS 0%puppet · puppetOct 27, 2011
- CVE-2013-165421Monitor
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol be
MediumCVSS 5.0No exploitEPSS 3%puppet · puppetMar 20, 2013
- CVE-2016-278721Monitor
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node
MediumCVSS 5.3No exploitEPSS 1%puppet · puppet enterpriseFeb 13, 2017
- CVE-2013-165220Monitor
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote a
MediumCVSS 4.9No exploitEPSS 2%puppet · puppetMar 20, 2013
- CVE-2013-476120Monitor
Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.
MediumCVSS 5.1No exploitEPSS 2%puppet · puppetAug 20, 2013
- CVE-2013-271620Monitor
Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upg
MediumCVSS 5.0No exploitEPSS 1%puppet · puppet enterpriseApr 10, 2013
- CVE-2011-384820Monitor
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Si
MediumCVSS 5.0No exploitEPSS 1%puppet · puppetOct 27, 2011
- CVE-2012-386718Monitor
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not proper
MediumCVSS 4.3No exploitEPSS 2%puppet · puppetAug 6, 2012
- CVE-2013-227517Monitor
The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupp
MediumCVSS 4.0No exploitEPSS 3%puppet · puppetMar 20, 2013
- CVE-2012-386417Monitor
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files
MediumCVSS 4.0No exploitEPSS 2%puppet · puppetAug 6, 2012
- CVE-2012-105417Monitor
Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a us
MediumCVSS 4.4No exploitEPSS 0%puppet · puppetMay 29, 2012
- CVE-2014-325117Monitor
The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new
MediumCVSS 4.4No exploitEPSS 0%puppet · puppet enterpriseAug 12, 2014
- CVE-2012-515816Monitor
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authentic
MediumCVSS 4.0No exploitEPSS 1%puppet · puppet enterpriseMar 14, 2014
- CVE-2012-386515Monitor
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befo
LowCVSS 3.5No exploitEPSS 2%puppet · puppetAug 6, 2012