VYPR

Vendor CVEs

Puppet (software)

All CVEs

136 total · sorted by risk
  • CVE-2018-11750MedOct 2, 2018
    risk 0.42cvss 6.5epss 0.01

    Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.

  • CVE-2017-10690MedFeb 9, 2018
    risk 0.42cvss 6.5epss 0.01

    In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4

  • CVE-2017-2296MedFeb 1, 2018
    risk 0.42cvss 6.5epss 0.01

    In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.

  • CVE-2015-8470MedDec 11, 2017
    risk 0.42cvss 6.5epss 0.02

    The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2014-3250MedDec 11, 2017
    risk 0.42cvss 6.5epss 0.01

    The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.

  • CVE-2017-2298MedJun 30, 2017
    risk 0.42cvss 6.5epss 0.01

    The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string…

  • CVE-2013-4968MedDec 11, 2019
    risk 0.40cvss 6.1epss 0.01

    Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."

  • CVE-2015-6502MedDec 11, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login Redirect.

  • CVE-2016-5715MedJan 12, 2017
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: this…

  • CVE-2015-6501MedJan 12, 2017
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.

  • CVE-2015-1855MedNov 29, 2019
    risk 0.39cvss 5.9epss 0.03

    verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards…

  • CVE-2022-0675MedMar 2, 2022
    risk 0.36cvss 5.6epss 0.01

    In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

  • CVE-2020-7945MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.

  • CVE-2018-11752MedOct 2, 2018
    risk 0.36cvss 5.5epss 0.00

    Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 release.

  • CVE-2018-11751MedDec 16, 2019
    risk 0.35cvss 5.4epss 0.01

    Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

  • CVE-2018-6511MedMay 8, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.

  • CVE-2018-6510MedMay 8, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator. Affected releases are Puppet Puppet Enterprise: 2017.3.x versions prior to 2017.3.6.

  • CVE-2016-9686MedFeb 8, 2017
    risk 0.35cvss 5.3epss 0.01

    The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.

  • CVE-2023-1894MedMay 4, 2023
    risk 0.34cvss 5.3epss 0.00

    A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

  • CVE-2016-2787MedFeb 13, 2017
    risk 0.34cvss 5.3epss 0.01

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

  • CVE-2021-27022MedSep 7, 2021
    risk 0.32cvss 4.9epss 0.01

    A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).

  • CVE-2017-2293MedFeb 1, 2018
    risk 0.32cvss 4.9epss 0.01

    Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who…

  • CVE-2015-7328MedJan 8, 2016
    risk 0.31cvss 4.7epss 0.00

    Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to…

  • CVE-2023-5255MedOct 3, 2023
    risk 0.29cvss 4.4epss 0.00

    For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

  • CVE-2021-27026MedNov 18, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

  • CVE-2017-10689MedFeb 9, 2018
    risk 0.29cvss 5.5epss 0.00

    In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

  • CVE-2013-0266MedMar 8, 2013
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading…

  • CVE-2021-27019MedAug 30, 2021
    risk 0.28cvss 4.3epss 0.01

    PuppetDB logging included potentially sensitive system information.

  • CVE-2022-2394MedJul 19, 2022
    risk 0.27cvss 4.1epss 0.01

    Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.

  • CVE-2015-1426Feb 23, 2015
    risk 0.00cvss epss 0.00

    Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

  • CVE-2014-9568Feb 3, 2015
    risk 0.00cvss epss 0.00

    puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter.

  • CVE-2015-1029Jan 16, 2015
    risk 0.00cvss epss 0.02

    The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

  • CVE-2014-9355Dec 19, 2014
    risk 0.00cvss epss 0.01

    Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request information by leveraging access to an unspecified API endpoint.

  • CVE-2014-7170Dec 17, 2014
    risk 0.00cvss epss 0.00

    Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

  • CVE-2014-3248Nov 16, 2014
    risk 0.00cvss epss 0.01

    Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain…

  • CVE-2014-3251Aug 12, 2014
    risk 0.00cvss epss 0.00

    The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified…

  • CVE-2014-3249Jun 17, 2014
    risk 0.00cvss epss 0.02

    Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.

  • CVE-2013-4963Mar 14, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.

  • CVE-2013-1399Mar 14, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet Enterprise (PE) before 2.7.1 allow remote attackers to hijack the authentication of unspecified…

  • CVE-2013-1398Mar 14, 2014
    risk 0.00cvss epss 0.02

    The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the…

  • CVE-2012-5158Mar 14, 2014
    risk 0.00cvss epss 0.01

    Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.

  • CVE-2012-0891Mar 14, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.

  • CVE-2013-4971Mar 9, 2014
    risk 0.00cvss epss 0.01

    Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2013-4966Mar 9, 2014
    risk 0.00cvss epss 0.01

    The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

  • CVE-2011-0528Feb 17, 2014
    risk 0.00cvss epss 0.02

    Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.

  • CVE-2013-4969Jan 7, 2014
    risk 0.00cvss epss 0.00

    Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.

  • CVE-2013-4965Oct 25, 2013
    risk 0.00cvss epss 0.01

    Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force attack.

  • CVE-2013-4957Oct 25, 2013
    risk 0.00cvss epss 0.01

    The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type.

  • CVE-2013-4967Aug 20, 2013
    risk 0.00cvss epss 0.01

    Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes.

  • CVE-2013-4964Aug 20, 2013
    risk 0.00cvss epss 0.02

    Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.