Bolt
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5214 | Med | 0.42 | 6.5 | 0.00 | Oct 6, 2023 | In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified. | ||
| CVE-2022-2394 | Med | 0.27 | 4.1 | 0.01 | Jul 19, 2022 | Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise. |
- risk 0.42cvss 6.5epss 0.00
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
- risk 0.27cvss 4.1epss 0.01
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.