İçeriğe atla
Noroxi

Puppet kayıtları

puppet üreticisine ait 128 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
10
Düzeltme kaydı olan
%50
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

128 kayıt
  • CVE-2017-7529
    49Planlayın

    Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultin

    YüksekCVSS 7,5Kavram kanıtıEPSS %63

    f5 · nginx13 Tem 2017

  • CVE-2016-2785
    40Planlayın

    Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to

    KritikCVSS 9,8İstismar yokEPSS %3

    puppet · puppet10 Haz 2016

  • CVE-2016-2788
    40Planlayın

    MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors relate

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · marionette collective13 Şub 2017

  • CVE-2022-3275
    40Planlayın

    Puppetlabs-apt Command Injection

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · puppetlabs-mysql7 Eki 2022

  • CVE-2014-0175
    40Planlayın

    mcollective has a default password set at install

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · marionette collective13 Ara 2019

  • CVE-2016-5713
    40Planlayın

    Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables th

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · puppet agent6 Ara 2017

  • CVE-2018-6512
    40Planlayın

    The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · pe-razor-server11 Haz 2018

  • CVE-2015-7224
    40Planlayın

    puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · puppetlabs-mysql21 Ara 2017

  • CVE-2016-2786
    39İzleyin

    The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server

    KritikCVSS 9,8İstismar yokEPSS %2

    puppet · puppet agent10 Haz 2016

  • CVE-2018-11746
    39İzleyin

    Puppet Discovery can leak authentication information

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · discovery3 Tem 2018

  • CVE-2021-27023
    39İzleyin

    A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a dif

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · puppet agent18 Kas 2021

  • CVE-2023-2530
    39İzleyin

    A privilege escalation allowing remote code execution was discovered in the orchestration service.

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · puppet enterprise7 Haz 2023

  • CVE-2019-10694
    39İzleyin

    The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admi

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · puppet enterprise11 Ara 2019

  • CVE-2022-0675
    39İzleyin

    Puppet Firewall Module May Leave Unmanaged Rules

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · firewall2 Mar 2022

  • CVE-2018-11749
    39İzleyin

    When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server.

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · puppet enterprise24 Ağu 2018

  • CVE-2018-11747
    39İzleyin

    Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container.

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · discovery21 Mar 2019

  • CVE-2023-5309
    39İzleyin

    Broken Session Management in Puppet Enterprise

    KritikCVSS 9,8İstismar yokEPSS %0

    puppet · puppet enterprise7 Kas 2023

  • CVE-2023-5214
    39İzleyin

    CVE-2023-5214 - Privilege Escalation in Puppet Bolt

    KritikCVSS 9,8İstismar yokEPSS %0

    puppet · bolt6 Eki 2023

  • CVE-2013-1640
    37İzleyin

    The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1

    KritikCVSS 9,0İstismar yokEPSS %5

    puppet · puppet20 Mar 2013

  • CVE-2017-2292
    37İzleyin

    Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code e

    KritikCVSS 9,0İstismar yokEPSS %2

    puppet · mcollective30 Haz 2017

  • CVE-2015-7330
    36İzleyin

    Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet co

    YüksekCVSS 8,8İstismar yokEPSS %2

    puppet · puppet enterprise11 Nis 2016

  • CVE-2016-5716
    36İzleyin

    The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code ex

    YüksekCVSS 8,8İstismar yokEPSS %2

    puppet · puppet enterprise9 Ağu 2017

  • CVE-2022-3276
    35İzleyin

    Puppetlabs-mysql Command Injection

    YüksekCVSS 8,8İstismar yokEPSS %2

    puppet · puppetlabs-mysql7 Eki 2022

  • CVE-2021-27021
    35İzleyin

    A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query

    YüksekCVSS 8,8İstismar yokEPSS %1

    puppet · puppet20 Tem 2021

  • CVE-2017-2290
    35İzleyin

    On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will

    YüksekCVSS 8,8İstismar yokEPSS %1

    puppet · mcollective-puppet-agent3 Mar 2017