Записи puppetlabs
34 опубликованных записей вендора puppetlabs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 82,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-20 Improper Input Validation3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-287 Improper Authentication2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-310 Cryptographic Issues2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2013-1398Эксплойта нет | The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which apuppet · puppet enterprise · CWE-310 | Высокая8,5 | — | 1,6 % | 14 мар. 2014 г. |
31Наблюдать | CVE-2013-1655Эксплойта нет | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vpuppet · puppet · CWE-20 | Высокая7,5 | — | 4,6 % | 20 мар. 2013 г. |
31Наблюдать | CVE-2013-3567Эксплойта нет | Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attapuppet · puppet · CWE-20 | Высокая7,5 | — | 3,4 % | 19 авг. 2013 г. |
30Наблюдать | CVE-2013-1653Эксплойта нет | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listeningpuppet · puppet | Высокая7,1 | — | 5,4 % | 20 мар. 2013 г. |
27Наблюдать | CVE-2013-2274Эксплойта нет | Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppepuppet · puppet | Средняя6,5 | — | 2,9 % | 20 мар. 2013 г. |
27Наблюдать | CVE-2013-1399Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administratpuppet · puppet enterprise · CWE-352 | Средняя6,8 | — | 0,6 % | 14 мар. 2014 г. |
27Наблюдать | CVE-2012-1053Эксплойта нет | The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppetpuppet · puppet · CWE-264 | Средняя6,9 | — | 0,4 % | 29 мая 2012 г. |
26Наблюдать | CVE-2015-7331Эксплойта нет | The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --spuppetlabs · mcollective-puppet-agent · CWE-254 | Средняя6,6 | — | 1,2 % | 30 янв. 2017 г. |
25Наблюдать | CVE-2011-3870Эксплойта нет | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attpuppet · puppet · CWE-59 | Средняя6,3 | — | 0,4 % | 27 окт. 2011 г. |
25Наблюдать | CVE-2011-3869Эксплойта нет | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lopuppet · puppet · CWE-59 | Средняя6,3 | — | 0,3 % | 27 окт. 2011 г. |
24Наблюдать | CVE-2014-3248Эксплойта нет | Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x bpuppet · facter · CWE-17 | Средняя6,2 | — | 0,5 % | 16 нояб. 2014 г. |
24Наблюдать | CVE-2011-3871Эксплойта нет | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local uspuppet · puppet · CWE-264 | Средняя6,2 | — | 0,3 % | 27 окт. 2011 г. |
21Наблюдать | CVE-2013-1654Эксплойта нет | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol bepuppet · puppet | Средняя5,0 | — | 2,9 % | 20 мар. 2013 г. |
21Наблюдать | CVE-2016-2787Эксплойта нет | The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker nodepuppet · puppet enterprise · CWE-284 | Средняя5,3 | — | 0,6 % | 13 февр. 2017 г. |
20Наблюдать | CVE-2013-1652Эксплойта нет | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote apuppet · puppet · CWE-264 | Средняя4,9 | — | 1,9 % | 20 мар. 2013 г. |
20Наблюдать | CVE-2013-4761Эксплойта нет | Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.puppet · puppet | Средняя5,1 | — | 1,6 % | 20 авг. 2013 г. |
20Наблюдать | CVE-2013-2716Эксплойта нет | Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgpuppet · puppet enterprise · CWE-310 | Средняя5,0 | — | 1,3 % | 10 апр. 2013 г. |
20Наблюдать | CVE-2011-3848Эксплойта нет | Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Sipuppet · puppet · CWE-22 | Средняя5,0 | — | 1,1 % | 27 окт. 2011 г. |
18Наблюдать | CVE-2012-3867Эксплойта нет | lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properpuppet · puppet · CWE-264 | Средняя4,3 | — | 2,5 % | 6 авг. 2012 г. |
17Наблюдать | CVE-2013-2275Эксплойта нет | The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupppuppet · puppet | Средняя4,0 | — | 2,9 % | 20 мар. 2013 г. |
17Наблюдать | CVE-2012-3864Эксплойта нет | Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files puppet · puppet · CWE-200 | Средняя4,0 | — | 1,9 % | 6 авг. 2012 г. |
17Наблюдать | CVE-2012-1054Эксплойта нет | Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a uspuppet · puppet · CWE-264 | Средняя4,4 | — | 0,4 % | 29 мая 2012 г. |
17Наблюдать | CVE-2014-3251Эксплойта нет | The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new puppet · puppet enterprise · CWE-362 | Средняя4,4 | — | 0,2 % | 12 авг. 2014 г. |
16Наблюдать | CVE-2012-5158Эксплойта нет | Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticpuppet · puppet enterprise · CWE-287 | Средняя4,0 | — | 0,8 % | 14 мар. 2014 г. |
15Наблюдать | CVE-2012-3865Эксплойта нет | Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befopuppet · puppet · CWE-22 | Низкая3,5 | — | 1,9 % | 6 авг. 2012 г. |
- CVE-2013-139834Наблюдать
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which a
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %puppet · puppet enterprise14 мар. 2014 г.
- CVE-2013-165531Наблюдать
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via v
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %puppet · puppet20 мар. 2013 г.
- CVE-2013-356731Наблюдать
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote atta
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %puppet · puppet19 авг. 2013 г.
- CVE-2013-165330Наблюдать
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening
ВысокаяCVSS 7,1Эксплойта нетEPSS 5 %puppet · puppet20 мар. 2013 г.
- CVE-2013-227427Наблюдать
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppe
СредняяCVSS 6,5Эксплойта нетEPSS 3 %puppet · puppet20 мар. 2013 г.
- CVE-2013-139927Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administrat
СредняяCVSS 6,8Эксплойта нетEPSS 1 %puppet · puppet enterprise14 мар. 2014 г.
- CVE-2012-105327Наблюдать
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet
СредняяCVSS 6,9Эксплойта нетEPSS 0 %puppet · puppet29 мая 2012 г.
- CVE-2015-733126Наблюдать
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --s
СредняяCVSS 6,6Эксплойта нетEPSS 1 %puppetlabs · mcollective-puppet-agent30 янв. 2017 г.
- CVE-2011-387025Наблюдать
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink att
СредняяCVSS 6,3Эксплойта нетEPSS 0 %puppet · puppet27 окт. 2011 г.
- CVE-2011-386925Наблюдать
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lo
СредняяCVSS 6,3Эксплойта нетEPSS 0 %puppet · puppet27 окт. 2011 г.
- CVE-2014-324824Наблюдать
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x b
СредняяCVSS 6,2Эксплойта нетEPSS 1 %puppet · facter16 нояб. 2014 г.
- CVE-2011-387124Наблюдать
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local us
СредняяCVSS 6,2Эксплойта нетEPSS 0 %puppet · puppet27 окт. 2011 г.
- CVE-2013-165421Наблюдать
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol be
СредняяCVSS 5,0Эксплойта нетEPSS 3 %puppet · puppet20 мар. 2013 г.
- CVE-2016-278721Наблюдать
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node
СредняяCVSS 5,3Эксплойта нетEPSS 1 %puppet · puppet enterprise13 февр. 2017 г.
- CVE-2013-165220Наблюдать
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote a
СредняяCVSS 4,9Эксплойта нетEPSS 2 %puppet · puppet20 мар. 2013 г.
- CVE-2013-476120Наблюдать
Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.
СредняяCVSS 5,1Эксплойта нетEPSS 2 %puppet · puppet20 авг. 2013 г.
- CVE-2013-271620Наблюдать
Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upg
СредняяCVSS 5,0Эксплойта нетEPSS 1 %puppet · puppet enterprise10 апр. 2013 г.
- CVE-2011-384820Наблюдать
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Si
СредняяCVSS 5,0Эксплойта нетEPSS 1 %puppet · puppet27 окт. 2011 г.
- CVE-2012-386718Наблюдать
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not proper
СредняяCVSS 4,3Эксплойта нетEPSS 2 %puppet · puppet6 авг. 2012 г.
- CVE-2013-227517Наблюдать
The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupp
СредняяCVSS 4,0Эксплойта нетEPSS 3 %puppet · puppet20 мар. 2013 г.
- CVE-2012-386417Наблюдать
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files
СредняяCVSS 4,0Эксплойта нетEPSS 2 %puppet · puppet6 авг. 2012 г.
- CVE-2012-105417Наблюдать
Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a us
СредняяCVSS 4,4Эксплойта нетEPSS 0 %puppet · puppet29 мая 2012 г.
- CVE-2014-325117Наблюдать
The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new
СредняяCVSS 4,4Эксплойта нетEPSS 0 %puppet · puppet enterprise12 авг. 2014 г.
- CVE-2012-515816Наблюдать
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authentic
СредняяCVSS 4,0Эксплойта нетEPSS 1 %puppet · puppet enterprise14 мар. 2014 г.
- CVE-2012-386515Наблюдать
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befo
НизкаяCVSS 3,5Эксплойта нетEPSS 2 %puppet · puppet6 авг. 2012 г.