Vulnerabilities > Puppet

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-5309 Session Fixation vulnerability in Puppet Enterprise
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.
network
low complexity
puppet CWE-384
critical
9.8
2023-10-06 CVE-2023-5214 Improper Privilege Management vulnerability in Puppet Bolt
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
network
low complexity
puppet CWE-269
critical
9.8
2023-10-03 CVE-2023-5255 Improper Resource Shutdown or Release vulnerability in Puppet and Puppet Server
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
network
low complexity
puppet CWE-404
7.5
2023-06-07 CVE-2023-2530 Unspecified vulnerability in Puppet Enterprise 2021.7.1/2023.0/2023.1.0
A privilege escalation allowing remote code execution was discovered in the orchestration service.
network
low complexity
puppet
critical
9.8
2023-05-04 CVE-2023-1894 Unspecified vulnerability in Puppet Enterprise and Puppet Server
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation.
network
low complexity
puppet
5.3
2022-10-07 CVE-2022-3275 Command injection is possible in the puppetlabs-apt module prior to version 9.0.0.
network
low complexity
puppet fedoraproject
critical
9.8
2022-10-07 CVE-2022-3276 Unspecified vulnerability in Puppet Puppetlabs-Mysql
Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0.
network
low complexity
puppet
8.8
2022-03-02 CVE-2022-0675 Improper Input Validation vulnerability in Puppet Firewall
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest.
network
low complexity
puppet CWE-20
critical
9.8
2021-11-18 CVE-2021-27023 A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host.
network
low complexity
puppet fedoraproject
critical
9.8
2021-11-18 CVE-2021-27024 Unspecified vulnerability in Puppet Continuous Delivery 4.0.0/4.0.1
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token.
network
low complexity
puppet
8.1