Puppet / Puppet Server
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-5255 | Denial of Service for Revocation of Auto Renewed Certificates | HIGH | 7.5 | Oct 3, 2023 |
| CVE-2023-1894 | puppet: Puppet Server ReDoS | MEDIUM | 5.3 | May 4, 2023 |
| CVE-2021-27023 | puppet: unsafe HTTP redirect | CRITICAL | 9.8 | Nov 18, 2021 |
| CVE-2020-7943 | puppet: puppet server and puppetDB may leak sensitive information via metrics API | HIGH | 7.5 | Mar 11, 2020 |
| CVE-2018-11751 | puppet-agent: Puppet Agent does not properly verify SSL connection when downloading a CRL | MEDIUM | 5.4 | Dec 16, 2019 |
| CVE-2017-2295 | puppet: Unsafe YAML deserialization | HIGH | 8.2 | Jul 5, 2017 |
| CVE-2016-2785 | puppet: incorrect URL decoding | CRITICAL | 9.8 | Jun 10, 2016 |
| CVE-2014-7170 | Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the sta… | LOW | 1.9 | Dec 17, 2014 |
Showing 1 to 7 of 7 CVEs