puppetlabs kayıtları
puppetlabs üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %82,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-20 Improper Input Validation3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-287 Improper Authentication2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-310 Cryptographic Issues2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2013-1398İstismar yok | The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which apuppet · puppet enterprise · CWE-310 | Yüksek8,5 | — | %1,6 | 14 Mar 2014 |
31İzleyin | CVE-2013-1655İstismar yok | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vpuppet · puppet · CWE-20 | Yüksek7,5 | — | %4,6 | 20 Mar 2013 |
31İzleyin | CVE-2013-3567İstismar yok | Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attapuppet · puppet · CWE-20 | Yüksek7,5 | — | %3,4 | 19 Ağu 2013 |
30İzleyin | CVE-2013-1653İstismar yok | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listeningpuppet · puppet | Yüksek7,1 | — | %5,4 | 20 Mar 2013 |
27İzleyin | CVE-2013-2274İstismar yok | Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppepuppet · puppet | Orta6,5 | — | %2,9 | 20 Mar 2013 |
27İzleyin | CVE-2013-1399İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administratpuppet · puppet enterprise · CWE-352 | Orta6,8 | — | %0,6 | 14 Mar 2014 |
27İzleyin | CVE-2012-1053İstismar yok | The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppetpuppet · puppet · CWE-264 | Orta6,9 | — | %0,4 | 29 May 2012 |
26İzleyin | CVE-2015-7331İstismar yok | The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --spuppetlabs · mcollective-puppet-agent · CWE-254 | Orta6,6 | — | %1,2 | 30 Oca 2017 |
25İzleyin | CVE-2011-3870İstismar yok | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attpuppet · puppet · CWE-59 | Orta6,3 | — | %0,4 | 27 Eki 2011 |
25İzleyin | CVE-2011-3869İstismar yok | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lopuppet · puppet · CWE-59 | Orta6,3 | — | %0,3 | 27 Eki 2011 |
24İzleyin | CVE-2014-3248İstismar yok | Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x bpuppet · facter · CWE-17 | Orta6,2 | — | %0,5 | 16 Kas 2014 |
24İzleyin | CVE-2011-3871İstismar yok | Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local uspuppet · puppet · CWE-264 | Orta6,2 | — | %0,3 | 27 Eki 2011 |
21İzleyin | CVE-2013-1654İstismar yok | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol bepuppet · puppet | Orta5,0 | — | %2,9 | 20 Mar 2013 |
21İzleyin | CVE-2016-2787İstismar yok | The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker nodepuppet · puppet enterprise · CWE-284 | Orta5,3 | — | %0,6 | 13 Şub 2017 |
20İzleyin | CVE-2013-1652İstismar yok | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote apuppet · puppet · CWE-264 | Orta4,9 | — | %1,9 | 20 Mar 2013 |
20İzleyin | CVE-2013-4761İstismar yok | Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.puppet · puppet | Orta5,1 | — | %1,6 | 20 Ağu 2013 |
20İzleyin | CVE-2013-2716İstismar yok | Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgpuppet · puppet enterprise · CWE-310 | Orta5,0 | — | %1,3 | 10 Nis 2013 |
20İzleyin | CVE-2011-3848İstismar yok | Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Sipuppet · puppet · CWE-22 | Orta5,0 | — | %1,1 | 27 Eki 2011 |
18İzleyin | CVE-2012-3867İstismar yok | lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properpuppet · puppet · CWE-264 | Orta4,3 | — | %2,5 | 6 Ağu 2012 |
17İzleyin | CVE-2013-2275İstismar yok | The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupppuppet · puppet | Orta4,0 | — | %2,9 | 20 Mar 2013 |
17İzleyin | CVE-2012-3864İstismar yok | Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files puppet · puppet · CWE-200 | Orta4,0 | — | %1,9 | 6 Ağu 2012 |
17İzleyin | CVE-2012-1054İstismar yok | Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a uspuppet · puppet · CWE-264 | Orta4,4 | — | %0,4 | 29 May 2012 |
17İzleyin | CVE-2014-3251İstismar yok | The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new puppet · puppet enterprise · CWE-362 | Orta4,4 | — | %0,2 | 12 Ağu 2014 |
16İzleyin | CVE-2012-5158İstismar yok | Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticpuppet · puppet enterprise · CWE-287 | Orta4,0 | — | %0,8 | 14 Mar 2014 |
15İzleyin | CVE-2012-3865İstismar yok | Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befopuppet · puppet · CWE-22 | Düşük3,5 | — | %1,9 | 6 Ağu 2012 |
- CVE-2013-139834İzleyin
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which a
YüksekCVSS 8,5İstismar yokEPSS %2puppet · puppet enterprise14 Mar 2014
- CVE-2013-165531İzleyin
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via v
YüksekCVSS 7,5İstismar yokEPSS %5puppet · puppet20 Mar 2013
- CVE-2013-356731İzleyin
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote atta
YüksekCVSS 7,5İstismar yokEPSS %3puppet · puppet19 Ağu 2013
- CVE-2013-165330İzleyin
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening
YüksekCVSS 7,1İstismar yokEPSS %5puppet · puppet20 Mar 2013
- CVE-2013-227427İzleyin
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppe
OrtaCVSS 6,5İstismar yokEPSS %3puppet · puppet20 Mar 2013
- CVE-2013-139927İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administrat
OrtaCVSS 6,8İstismar yokEPSS %1puppet · puppet enterprise14 Mar 2014
- CVE-2012-105327İzleyin
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet
OrtaCVSS 6,9İstismar yokEPSS %0puppet · puppet29 May 2012
- CVE-2015-733126İzleyin
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --s
OrtaCVSS 6,6İstismar yokEPSS %1puppetlabs · mcollective-puppet-agent30 Oca 2017
- CVE-2011-387025İzleyin
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink att
OrtaCVSS 6,3İstismar yokEPSS %0puppet · puppet27 Eki 2011
- CVE-2011-386925İzleyin
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5lo
OrtaCVSS 6,3İstismar yokEPSS %0puppet · puppet27 Eki 2011
- CVE-2014-324824İzleyin
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x b
OrtaCVSS 6,2İstismar yokEPSS %1puppet · facter16 Kas 2014
- CVE-2011-387124İzleyin
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local us
OrtaCVSS 6,2İstismar yokEPSS %0puppet · puppet27 Eki 2011
- CVE-2013-165421İzleyin
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol be
OrtaCVSS 5,0İstismar yokEPSS %3puppet · puppet20 Mar 2013
- CVE-2016-278721İzleyin
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node
OrtaCVSS 5,3İstismar yokEPSS %1puppet · puppet enterprise13 Şub 2017
- CVE-2013-165220İzleyin
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote a
OrtaCVSS 4,9İstismar yokEPSS %2puppet · puppet20 Mar 2013
- CVE-2013-476120İzleyin
Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.
OrtaCVSS 5,1İstismar yokEPSS %2puppet · puppet20 Ağu 2013
- CVE-2013-271620İzleyin
Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upg
OrtaCVSS 5,0İstismar yokEPSS %1puppet · puppet enterprise10 Nis 2013
- CVE-2011-384820İzleyin
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Si
OrtaCVSS 5,0İstismar yokEPSS %1puppet · puppet27 Eki 2011
- CVE-2012-386718İzleyin
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not proper
OrtaCVSS 4,3İstismar yokEPSS %2puppet · puppet6 Ağu 2012
- CVE-2013-227517İzleyin
The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pupp
OrtaCVSS 4,0İstismar yokEPSS %3puppet · puppet20 Mar 2013
- CVE-2012-386417İzleyin
Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files
OrtaCVSS 4,0İstismar yokEPSS %2puppet · puppet6 Ağu 2012
- CVE-2012-105417İzleyin
Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a us
OrtaCVSS 4,4İstismar yokEPSS %0puppet · puppet29 May 2012
- CVE-2014-325117İzleyin
The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new
OrtaCVSS 4,4İstismar yokEPSS %0puppet · puppet enterprise12 Ağu 2014
- CVE-2012-515816İzleyin
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authentic
OrtaCVSS 4,0İstismar yokEPSS %1puppet · puppet enterprise14 Mar 2014
- CVE-2012-386515İzleyin
Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise befo
DüşükCVSS 3,5İstismar yokEPSS %2puppet · puppet6 Ağu 2012