Puppet kayıtları
puppet üreticisine ait 128 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls14
- CWE-20 Improper Input Validation12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-295 Improper Certificate Validation8
- CWE-287 Improper Authentication7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
128 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2017-7529Kavram kanıtı | Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultinf5 · nginx · CWE-190 | Yüksek7,5 | — | %62,6 | 13 Tem 2017 |
40Planlayın | CVE-2016-2785İstismar yok | Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers topuppet · puppet · CWE-284 | Kritik9,8 | — | %2,9 | 10 Haz 2016 |
40Planlayın | CVE-2016-2788İstismar yok | MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relatepuppet · marionette collective · CWE-284 | Kritik9,8 | — | %2,3 | 13 Şub 2017 |
40Planlayın | CVE-2022-3275İstismar yok | Puppetlabs-apt Command Injectionpuppet · puppetlabs-mysql · CWE-78 | Kritik9,8 | — | %2,2 | 7 Eki 2022 |
40Planlayın | CVE-2014-0175İstismar yok | mcollective has a default password set at installpuppet · marionette collective · CWE-798 | Kritik9,8 | — | %2,0 | 13 Ara 2019 |
40Planlayın | CVE-2016-5713İstismar yok | Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables thpuppet · puppet agent · CWE-94 | Kritik9,8 | — | %2,0 | 6 Ara 2017 |
40Planlayın | CVE-2018-6512İstismar yok | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.puppet · pe-razor-server · CWE-94 | Kritik9,8 | — | %1,9 | 11 Haz 2018 |
40Planlayın | CVE-2015-7224İstismar yok | puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a puppet · puppetlabs-mysql · CWE-287 | Kritik9,8 | — | %1,7 | 21 Ara 2017 |
39İzleyin | CVE-2016-2786İstismar yok | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server puppet · puppet agent · CWE-20 | Kritik9,8 | — | %1,6 | 10 Haz 2016 |
39İzleyin | CVE-2018-11746İstismar yok | Puppet Discovery can leak authentication informationpuppet · discovery · CWE-522 | Kritik9,8 | — | %1,4 | 3 Tem 2018 |
39İzleyin | CVE-2021-27023İstismar yok | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a difpuppet · puppet agent | Kritik9,8 | — | %1,4 | 18 Kas 2021 |
39İzleyin | CVE-2023-2530İstismar yok | A privilege escalation allowing remote code execution was discovered in the orchestration service.puppet · puppet enterprise · CWE-284 | Kritik9,8 | — | %1,1 | 7 Haz 2023 |
39İzleyin | CVE-2019-10694İstismar yok | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admipuppet · puppet enterprise · CWE-798 | Kritik9,8 | — | %1,1 | 11 Ara 2019 |
39İzleyin | CVE-2022-0675İstismar yok | Puppet Firewall Module May Leave Unmanaged Rulespuppet · firewall · CWE-1289 | Kritik9,8 | — | %0,9 | 2 Mar 2022 |
39İzleyin | CVE-2018-11749İstismar yok | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.puppet · puppet enterprise · CWE-319 | Kritik9,8 | — | %0,8 | 24 Ağu 2018 |
39İzleyin | CVE-2018-11747İstismar yok | Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.puppet · discovery · CWE-295 | Kritik9,8 | — | %0,7 | 21 Mar 2019 |
39İzleyin | CVE-2023-5309İstismar yok | Broken Session Management in Puppet Enterprisepuppet · puppet enterprise · CWE-384 | Kritik9,8 | — | %0,5 | 7 Kas 2023 |
39İzleyin | CVE-2023-5214İstismar yok | CVE-2023-5214 - Privilege Escalation in Puppet Boltpuppet · bolt · CWE-269 | Kritik9,8 | — | %0,4 | 6 Eki 2023 |
37İzleyin | CVE-2013-1640İstismar yok | The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1puppet · puppet | Kritik9,0 | — | %4,9 | 20 Mar 2013 |
37İzleyin | CVE-2017-2292İstismar yok | Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code epuppet · mcollective · CWE-502 | Kritik9,0 | — | %2,2 | 30 Haz 2017 |
36İzleyin | CVE-2015-7330İstismar yok | Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet copuppet · puppet enterprise · CWE-254 | Yüksek8,8 | — | %2,1 | 11 Nis 2016 |
36İzleyin | CVE-2016-5716İstismar yok | The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code expuppet · puppet enterprise · CWE-134 | Yüksek8,8 | — | %1,8 | 9 Ağu 2017 |
35İzleyin | CVE-2022-3276İstismar yok | Puppetlabs-mysql Command Injectionpuppet · puppetlabs-mysql · CWE-78 | Yüksek8,8 | — | %1,7 | 7 Eki 2022 |
35İzleyin | CVE-2021-27021İstismar yok | A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL querypuppet · puppet · CWE-1027 | Yüksek8,8 | — | %1,3 | 20 Tem 2021 |
35İzleyin | CVE-2017-2290İstismar yok | On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that willpuppet · mcollective-puppet-agent · CWE-732 | Yüksek8,8 | — | %1,2 | 3 Mar 2017 |
- CVE-2017-752949Planlayın
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultin
YüksekCVSS 7,5Kavram kanıtıEPSS %63f5 · nginx13 Tem 2017
- CVE-2016-278540Planlayın
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to
KritikCVSS 9,8İstismar yokEPSS %3puppet · puppet10 Haz 2016
- CVE-2016-278840Planlayın
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relate
KritikCVSS 9,8İstismar yokEPSS %2puppet · marionette collective13 Şub 2017
- CVE-2022-327540Planlayın
Puppetlabs-apt Command Injection
KritikCVSS 9,8İstismar yokEPSS %2puppet · puppetlabs-mysql7 Eki 2022
- CVE-2014-017540Planlayın
mcollective has a default password set at install
KritikCVSS 9,8İstismar yokEPSS %2puppet · marionette collective13 Ara 2019
- CVE-2016-571340Planlayın
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables th
KritikCVSS 9,8İstismar yokEPSS %2puppet · puppet agent6 Ara 2017
- CVE-2018-651240Planlayın
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.
KritikCVSS 9,8İstismar yokEPSS %2puppet · pe-razor-server11 Haz 2018
- CVE-2015-722440Planlayın
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a
KritikCVSS 9,8İstismar yokEPSS %2puppet · puppetlabs-mysql21 Ara 2017
- CVE-2016-278639İzleyin
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server
KritikCVSS 9,8İstismar yokEPSS %2puppet · puppet agent10 Haz 2016
- CVE-2018-1174639İzleyin
Puppet Discovery can leak authentication information
KritikCVSS 9,8İstismar yokEPSS %1puppet · discovery3 Tem 2018
- CVE-2021-2702339İzleyin
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a dif
KritikCVSS 9,8İstismar yokEPSS %1puppet · puppet agent18 Kas 2021
- CVE-2023-253039İzleyin
A privilege escalation allowing remote code execution was discovered in the orchestration service.
KritikCVSS 9,8İstismar yokEPSS %1puppet · puppet enterprise7 Haz 2023
- CVE-2019-1069439İzleyin
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admi
KritikCVSS 9,8İstismar yokEPSS %1puppet · puppet enterprise11 Ara 2019
- CVE-2022-067539İzleyin
Puppet Firewall Module May Leave Unmanaged Rules
KritikCVSS 9,8İstismar yokEPSS %1puppet · firewall2 Mar 2022
- CVE-2018-1174939İzleyin
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.
KritikCVSS 9,8İstismar yokEPSS %1puppet · puppet enterprise24 Ağu 2018
- CVE-2018-1174739İzleyin
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.
KritikCVSS 9,8İstismar yokEPSS %1puppet · discovery21 Mar 2019
- CVE-2023-530939İzleyin
Broken Session Management in Puppet Enterprise
KritikCVSS 9,8İstismar yokEPSS %0puppet · puppet enterprise7 Kas 2023
- CVE-2023-521439İzleyin
CVE-2023-5214 - Privilege Escalation in Puppet Bolt
KritikCVSS 9,8İstismar yokEPSS %0puppet · bolt6 Eki 2023
- CVE-2013-164037İzleyin
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1
KritikCVSS 9,0İstismar yokEPSS %5puppet · puppet20 Mar 2013
- CVE-2017-229237İzleyin
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code e
KritikCVSS 9,0İstismar yokEPSS %2puppet · mcollective30 Haz 2017
- CVE-2015-733036İzleyin
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet co
YüksekCVSS 8,8İstismar yokEPSS %2puppet · puppet enterprise11 Nis 2016
- CVE-2016-571636İzleyin
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code ex
YüksekCVSS 8,8İstismar yokEPSS %2puppet · puppet enterprise9 Ağu 2017
- CVE-2022-327635İzleyin
Puppetlabs-mysql Command Injection
YüksekCVSS 8,8İstismar yokEPSS %2puppet · puppetlabs-mysql7 Eki 2022
- CVE-2021-2702135İzleyin
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query
YüksekCVSS 8,8İstismar yokEPSS %1puppet · puppet20 Tem 2021
- CVE-2017-229035İzleyin
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will
YüksekCVSS 8,8İstismar yokEPSS %1puppet · mcollective-puppet-agent3 Mar 2017