Vulnerabilities > Puppet > Puppet > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-03 CVE-2023-5255 Improper Resource Shutdown or Release vulnerability in Puppet and Puppet Server
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
network
low complexity
puppet CWE-404
7.5
2021-07-20 CVE-2021-27021 SQL Injection vulnerability in Puppet and Puppetdb
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
network
low complexity
puppet CWE-89
8.8
2018-06-11 CVE-2018-6515 Improper Input Validation vulnerability in Puppet
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
local
low complexity
puppet CWE-20
7.8
2018-06-11 CVE-2018-6514 Untrusted Search Path vulnerability in Puppet
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.
local
low complexity
puppet CWE-426
7.8
2018-06-11 CVE-2018-6513 Untrusted Search Path vulnerability in Puppet and Puppet Enterprise
Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet run.
network
low complexity
puppet CWE-426
8.8
2017-07-05 CVE-2017-2295 Deserialization of Untrusted Data vulnerability in multiple products
Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format.
network
high complexity
puppet debian CWE-502
8.2