İçeriğe atla
Noroxi

puppetlabs kayıtları

puppetlabs üreticisine ait 34 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%82,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

34 kayıt
  • CVE-2013-1398
    34İzleyin

    The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which a

    YüksekCVSS 8,5İstismar yokEPSS %2

    puppet · puppet enterprise14 Mar 2014

  • CVE-2013-1655
    31İzleyin

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via v

    YüksekCVSS 7,5İstismar yokEPSS %5

    puppet · puppet20 Mar 2013

  • CVE-2013-3567
    31İzleyin

    Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote atta

    YüksekCVSS 7,5İstismar yokEPSS %3

    puppet · puppet19 Ağu 2013

  • CVE-2013-1653
    30İzleyin

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening

    YüksekCVSS 7,1İstismar yokEPSS %5

    puppet · puppet20 Mar 2013

  • CVE-2013-2274
    27İzleyin

    Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppe

    OrtaCVSS 6,5İstismar yokEPSS %3

    puppet · puppet20 Mar 2013

  • CVE-2013-1399
    27İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administrat

    OrtaCVSS 6,8İstismar yokEPSS %1

    puppet · puppet enterprise14 Mar 2014

  • CVE-2012-1053
    27İzleyin

    The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet

    OrtaCVSS 6,9İstismar yokEPSS %0

    puppet · puppet29 May 2012

  • CVE-2015-7331
    26İzleyin

    The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --s

    OrtaCVSS 6,6İstismar yokEPSS %1

    puppetlabs · mcollective-puppet-agent30 Oca 2017

  • CVE-2011-3870
    25İzleyin

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink att

    OrtaCVSS 6,3İstismar yokEPSS %0

    puppet · puppet27 Eki 2011

  • CVE-2011-3869
    25İzleyin

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lo

    OrtaCVSS 6,3İstismar yokEPSS %0

    puppet · puppet27 Eki 2011

  • CVE-2014-3248
    24İzleyin

    Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x b

    OrtaCVSS 6,2İstismar yokEPSS %1

    puppet · facter16 Kas 2014

  • CVE-2011-3871
    24İzleyin

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local us

    OrtaCVSS 6,2İstismar yokEPSS %0

    puppet · puppet27 Eki 2011

  • CVE-2013-1654
    21İzleyin

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol be

    OrtaCVSS 5,0İstismar yokEPSS %3

    puppet · puppet20 Mar 2013

  • CVE-2016-2787
    21İzleyin

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node

    OrtaCVSS 5,3İstismar yokEPSS %1

    puppet · puppet enterprise13 Şub 2017

  • CVE-2013-1652
    20İzleyin

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote a

    OrtaCVSS 4,9İstismar yokEPSS %2

    puppet · puppet20 Mar 2013

  • CVE-2013-4761
    20İzleyin

    Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.

    OrtaCVSS 5,1İstismar yokEPSS %2

    puppet · puppet20 Ağu 2013

  • CVE-2013-2716
    20İzleyin

    Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upg

    OrtaCVSS 5,0İstismar yokEPSS %1

    puppet · puppet enterprise10 Nis 2013

  • CVE-2011-3848
    20İzleyin

    Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Si

    OrtaCVSS 5,0İstismar yokEPSS %1

    puppet · puppet27 Eki 2011

  • CVE-2012-3867
    18İzleyin

    lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not proper

    OrtaCVSS 4,3İstismar yokEPSS %2

    puppet · puppet6 Ağu 2012

  • CVE-2013-2275
    17İzleyin

    The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupp

    OrtaCVSS 4,0İstismar yokEPSS %3

    puppet · puppet20 Mar 2013

  • CVE-2012-3864
    17İzleyin

    Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files

    OrtaCVSS 4,0İstismar yokEPSS %2

    puppet · puppet6 Ağu 2012

  • CVE-2012-1054
    17İzleyin

    Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a us

    OrtaCVSS 4,4İstismar yokEPSS %0

    puppet · puppet29 May 2012

  • CVE-2014-3251
    17İzleyin

    The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new

    OrtaCVSS 4,4İstismar yokEPSS %0

    puppet · puppet enterprise12 Ağu 2014

  • CVE-2012-5158
    16İzleyin

    Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authentic

    OrtaCVSS 4,0İstismar yokEPSS %1

    puppet · puppet enterprise14 Mar 2014

  • CVE-2012-3865
    15İzleyin

    Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befo

    DüşükCVSS 3,5İstismar yokEPSS %2

    puppet · puppet6 Ağu 2012