Puppet / Puppet Agent
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-27023 | puppet: unsafe HTTP redirect | CRITICAL | 9.8 | Nov 18, 2021 |
| CVE-2021-27025 | puppet: silent configuration failure in agent | MEDIUM | 6.5 | Nov 18, 2021 |
| CVE-2020-7942 | puppet: Arbitrary catalog retrieval | MEDIUM | 6.5 | Feb 19, 2020 |
| CVE-2015-1855 | ruby: OpenSSL extension hostname matching implementation violates RFC 6125 | MEDIUM | 5.9 | Nov 29, 2019 |
| CVE-2018-6515 | puppet-agent: pxp-agent attempts to configure OpenSSL from uncontrolled location | HIGH | 8.8 | Jun 11, 2018 |
| CVE-2018-6514 | puppet-agent: Facter tries to load DLLs from the current working directory | HIGH | 7.8 | Jun 11, 2018 |
| CVE-2017-10690 | puppet: Environment leakage in puppet-agent | MEDIUM | 6.5 | Feb 9, 2018 |
| CVE-2017-10689 | puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions | MEDIUM | 5.5 | Feb 9, 2018 |
| CVE-2016-5713 | Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet run… | CRITICAL | 9.8 | Dec 6, 2017 |
| CVE-2016-5714 | Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechan… | HIGH | 7.2 | Oct 18, 2017 |
| CVE-2016-2786 | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which… | CRITICAL | 9.8 | Jun 10, 2016 |
| CVE-2016-2785 | puppet: incorrect URL decoding | CRITICAL | 9.8 | Jun 10, 2016 |
Showing 1 to 8 of 8 CVEs