CVE Browser
OS Command Injection
Security Misconfiguration in Forge module PEADM
Broken Session Management in Puppet Enterprise
CVE-2023-5214 - Privilege Escalation in Puppet Bolt
Denial of Service for Revocation of Auto Renewed Certificates
A privilege escalation allowing remote code execution was discovered in the orchestration service.
puppet: Puppet Server ReDoS
Puppetlabs-mysql Command Injection
Puppetlabs-apt Command Injection
Sensitive Parameter Exposure in Puppet Bolt prior to 3.24
Puppet Firewall Module May Leave Unmanaged Rules
puppet: unsafe HTTP redirect
puppet: silent configuration failure in agent
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterpris…
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should…
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to…
PuppetDB logging included potentially sensitive system information.
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
puppet: SQL injection
puppet: local registry credentials included in CD4PE deployment definition leads to expose credentials to users who should not have access
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive…
puppet: puppet server and puppetDB may leak sensitive information via metrics API
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an atta…
puppet: Arbitrary catalog retrieval
Showing 1 to 25 CVEs · page 1 (more available)