CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Puppet Remove filter Clear all
CVE-2025-5459 HIGH

OS Command Injection

CVSS 8.6 EPSS 1.06% Jun 26, 2025
CVE-2024-9160 MEDIUM

Security Misconfiguration in Forge module PEADM

CVSS 5.4 EPSS 0.17% Sep 27, 2024
CVE-2023-5309 CRITICAL

Broken Session Management in Puppet Enterprise

CVSS 9.8 EPSS 0.50% Nov 7, 2023
CVE-2023-5214 CRITICAL

CVE-2023-5214 - Privilege Escalation in Puppet Bolt

CVSS 9.8 EPSS 0.37% Oct 6, 2023
CVE-2023-5255 HIGH

Denial of Service for Revocation of Auto Renewed Certificates

CVSS 7.5 EPSS 0.48% Oct 3, 2023
CVE-2023-2530 CRITICAL

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CVSS 9.8 EPSS 1.11% Jun 7, 2023
CVE-2023-1894 MEDIUM

puppet: Puppet Server ReDoS

CVSS 5.3 EPSS 0.44% May 4, 2023
CVE-2022-3276 HIGH

Puppetlabs-mysql Command Injection

CVSS 8.8 EPSS 1.68% Oct 7, 2022
CVE-2022-3275 CRITICAL

Puppetlabs-apt Command Injection

CVSS 9.8 EPSS 2.31% Oct 7, 2022
CVE-2022-2394 MEDIUM

Sensitive Parameter Exposure in Puppet Bolt prior to 3.24

CVSS 4.1 EPSS 0.54% Jul 19, 2022
CVE-2022-0675 CRITICAL

Puppet Firewall Module May Leave Unmanaged Rules

CVSS 9.8 EPSS 0.92% Mar 2, 2022
CVE-2021-27023 CRITICAL

puppet: unsafe HTTP redirect

CVSS 9.8 EPSS 1.37% Nov 18, 2021
CVE-2021-27025 MEDIUM

puppet: silent configuration failure in agent

CVSS 6.5 EPSS 1.11% Nov 18, 2021
CVE-2021-27026 MEDIUM

A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

CVSS 4.4 EPSS 0.25% Nov 18, 2021
CVE-2021-27024 HIGH

A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterpris…

CVSS 8.1 EPSS 0.82% Nov 18, 2021
CVE-2021-27022 MEDIUM

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should…

CVSS 4.9 EPSS 0.92% Sep 7, 2021
CVE-2021-27018 HIGH

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to…

CVSS 7.5 EPSS 0.54% Aug 30, 2021
CVE-2021-27019 MEDIUM

PuppetDB logging included potentially sensitive system information.

CVSS 4.3 EPSS 0.74% Aug 30, 2021
CVE-2021-27020 HIGH

Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.

CVSS 8.8 EPSS 1.06% Aug 30, 2021
CVE-2021-27021 HIGH

puppet: SQL injection

CVSS 8.9 EPSS 1.26% Jul 20, 2021
CVE-2020-7945 MEDIUM

puppet: local registry credentials included in CD4PE deployment definition leads to expose credentials to users who should not have access

CVSS 5.5 EPSS 0.31% Sep 18, 2020
CVE-2020-7944 HIGH

In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive…

CVSS 7.7 EPSS 0.86% Mar 26, 2020
CVE-2020-7943 HIGH

puppet: puppet server and puppetDB may leak sensitive information via metrics API

CVSS 7.5 EPSS 8.81% Mar 11, 2020
CVE-2015-5686 HIGH

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an atta…

CVSS 8.8 EPSS 0.45% Feb 27, 2020
CVE-2020-7942 MEDIUM

puppet: Arbitrary catalog retrieval

CVSS 6.5 EPSS 0.82% Feb 19, 2020

Showing 1 to 25 CVEs · page 1 (more available)