Записи Puppet
128 опубликованных записей вендора puppet.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls14
- CWE-20 Improper Input Validation12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-295 Improper Certificate Validation8
- CWE-287 Improper Authentication7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
128 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2017-7529Proof of concept | Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultinf5 · nginx · CWE-190 | Высокая7,5 | — | 62,6 % | 13 июл. 2017 г. |
40В плане | CVE-2016-2785Эксплойта нет | Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers topuppet · puppet · CWE-284 | Критическая9,8 | — | 2,9 % | 10 июн. 2016 г. |
40В плане | CVE-2016-2788Эксплойта нет | MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relatepuppet · marionette collective · CWE-284 | Критическая9,8 | — | 2,3 % | 13 февр. 2017 г. |
40В плане | CVE-2022-3275Эксплойта нет | Puppetlabs-apt Command Injectionpuppet · puppetlabs-mysql · CWE-78 | Критическая9,8 | — | 2,2 % | 7 окт. 2022 г. |
40В плане | CVE-2014-0175Эксплойта нет | mcollective has a default password set at installpuppet · marionette collective · CWE-798 | Критическая9,8 | — | 2,0 % | 13 дек. 2019 г. |
40В плане | CVE-2016-5713Эксплойта нет | Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables thpuppet · puppet agent · CWE-94 | Критическая9,8 | — | 2,0 % | 6 дек. 2017 г. |
40В плане | CVE-2018-6512Эксплойта нет | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.puppet · pe-razor-server · CWE-94 | Критическая9,8 | — | 1,9 % | 11 июн. 2018 г. |
40В плане | CVE-2015-7224Эксплойта нет | puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a puppet · puppetlabs-mysql · CWE-287 | Критическая9,8 | — | 1,7 % | 21 дек. 2017 г. |
39Наблюдать | CVE-2016-2786Эксплойта нет | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server puppet · puppet agent · CWE-20 | Критическая9,8 | — | 1,6 % | 10 июн. 2016 г. |
39Наблюдать | CVE-2018-11746Эксплойта нет | Puppet Discovery can leak authentication informationpuppet · discovery · CWE-522 | Критическая9,8 | — | 1,4 % | 3 июл. 2018 г. |
39Наблюдать | CVE-2021-27023Эксплойта нет | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a difpuppet · puppet agent | Критическая9,8 | — | 1,4 % | 18 нояб. 2021 г. |
39Наблюдать | CVE-2023-2530Эксплойта нет | A privilege escalation allowing remote code execution was discovered in the orchestration service.puppet · puppet enterprise · CWE-284 | Критическая9,8 | — | 1,1 % | 7 июн. 2023 г. |
39Наблюдать | CVE-2019-10694Эксплойта нет | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admipuppet · puppet enterprise · CWE-798 | Критическая9,8 | — | 1,1 % | 11 дек. 2019 г. |
39Наблюдать | CVE-2022-0675Эксплойта нет | Puppet Firewall Module May Leave Unmanaged Rulespuppet · firewall · CWE-1289 | Критическая9,8 | — | 0,9 % | 2 мар. 2022 г. |
39Наблюдать | CVE-2018-11749Эксплойта нет | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.puppet · puppet enterprise · CWE-319 | Критическая9,8 | — | 0,8 % | 24 авг. 2018 г. |
39Наблюдать | CVE-2018-11747Эксплойта нет | Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.puppet · discovery · CWE-295 | Критическая9,8 | — | 0,7 % | 21 мар. 2019 г. |
39Наблюдать | CVE-2023-5309Эксплойта нет | Broken Session Management in Puppet Enterprisepuppet · puppet enterprise · CWE-384 | Критическая9,8 | — | 0,5 % | 7 нояб. 2023 г. |
39Наблюдать | CVE-2023-5214Эксплойта нет | CVE-2023-5214 - Privilege Escalation in Puppet Boltpuppet · bolt · CWE-269 | Критическая9,8 | — | 0,4 % | 6 окт. 2023 г. |
37Наблюдать | CVE-2013-1640Эксплойта нет | The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1puppet · puppet | Критическая9,0 | — | 4,9 % | 20 мар. 2013 г. |
37Наблюдать | CVE-2017-2292Эксплойта нет | Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code epuppet · mcollective · CWE-502 | Критическая9,0 | — | 2,2 % | 30 июн. 2017 г. |
36Наблюдать | CVE-2015-7330Эксплойта нет | Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet copuppet · puppet enterprise · CWE-254 | Высокая8,8 | — | 2,1 % | 11 апр. 2016 г. |
36Наблюдать | CVE-2016-5716Эксплойта нет | The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code expuppet · puppet enterprise · CWE-134 | Высокая8,8 | — | 1,8 % | 9 авг. 2017 г. |
35Наблюдать | CVE-2022-3276Эксплойта нет | Puppetlabs-mysql Command Injectionpuppet · puppetlabs-mysql · CWE-78 | Высокая8,8 | — | 1,7 % | 7 окт. 2022 г. |
35Наблюдать | CVE-2021-27021Эксплойта нет | A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL querypuppet · puppet · CWE-1027 | Высокая8,8 | — | 1,3 % | 20 июл. 2021 г. |
35Наблюдать | CVE-2017-2290Эксплойта нет | On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that willpuppet · mcollective-puppet-agent · CWE-732 | Высокая8,8 | — | 1,2 % | 3 мар. 2017 г. |
- CVE-2017-752949В плане
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultin
ВысокаяCVSS 7,5Proof of conceptEPSS 63 %f5 · nginx13 июл. 2017 г.
- CVE-2016-278540В плане
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %puppet · puppet10 июн. 2016 г.
- CVE-2016-278840В плане
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relate
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · marionette collective13 февр. 2017 г.
- CVE-2022-327540В плане
Puppetlabs-apt Command Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · puppetlabs-mysql7 окт. 2022 г.
- CVE-2014-017540В плане
mcollective has a default password set at install
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · marionette collective13 дек. 2019 г.
- CVE-2016-571340В плане
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables th
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · puppet agent6 дек. 2017 г.
- CVE-2018-651240В плане
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · pe-razor-server11 июн. 2018 г.
- CVE-2015-722440В плане
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · puppetlabs-mysql21 дек. 2017 г.
- CVE-2016-278639Наблюдать
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppet · puppet agent10 июн. 2016 г.
- CVE-2018-1174639Наблюдать
Puppet Discovery can leak authentication information
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · discovery3 июл. 2018 г.
- CVE-2021-2702339Наблюдать
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a dif
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · puppet agent18 нояб. 2021 г.
- CVE-2023-253039Наблюдать
A privilege escalation allowing remote code execution was discovered in the orchestration service.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · puppet enterprise7 июн. 2023 г.
- CVE-2019-1069439Наблюдать
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · puppet enterprise11 дек. 2019 г.
- CVE-2022-067539Наблюдать
Puppet Firewall Module May Leave Unmanaged Rules
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · firewall2 мар. 2022 г.
- CVE-2018-1174939Наблюдать
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · puppet enterprise24 авг. 2018 г.
- CVE-2018-1174739Наблюдать
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %puppet · discovery21 мар. 2019 г.
- CVE-2023-530939Наблюдать
Broken Session Management in Puppet Enterprise
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %puppet · puppet enterprise7 нояб. 2023 г.
- CVE-2023-521439Наблюдать
CVE-2023-5214 - Privilege Escalation in Puppet Bolt
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %puppet · bolt6 окт. 2023 г.
- CVE-2013-164037Наблюдать
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1
КритическаяCVSS 9,0Эксплойта нетEPSS 5 %puppet · puppet20 мар. 2013 г.
- CVE-2017-229237Наблюдать
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code e
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %puppet · mcollective30 июн. 2017 г.
- CVE-2015-733036Наблюдать
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet co
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %puppet · puppet enterprise11 апр. 2016 г.
- CVE-2016-571636Наблюдать
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code ex
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %puppet · puppet enterprise9 авг. 2017 г.
- CVE-2022-327635Наблюдать
Puppetlabs-mysql Command Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %puppet · puppetlabs-mysql7 окт. 2022 г.
- CVE-2021-2702135Наблюдать
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %puppet · puppet20 июл. 2021 г.
- CVE-2017-229035Наблюдать
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %puppet · mcollective-puppet-agent3 мар. 2017 г.