Puppet / Puppet Enterprise
89 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-5459 | OS Command Injection | HIGH | 8.6 | Jun 26, 2025 |
| CVE-2023-5309 | Broken Session Management in Puppet Enterprise | CRITICAL | 9.8 | Nov 7, 2023 |
| CVE-2023-5255 | Denial of Service for Revocation of Auto Renewed Certificates | HIGH | 7.5 | Oct 3, 2023 |
| CVE-2023-2530 | A privilege escalation allowing remote code execution was discovered in the orchestration service. | CRITICAL | 9.8 | Jun 7, 2023 |
| CVE-2023-1894 | puppet: Puppet Server ReDoS | MEDIUM | 5.3 | May 4, 2023 |
| CVE-2021-27023 | puppet: unsafe HTTP redirect | CRITICAL | 9.8 | Nov 18, 2021 |
| CVE-2021-27025 | puppet: silent configuration failure in agent | MEDIUM | 6.5 | Nov 18, 2021 |
| CVE-2021-27026 | A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged | MEDIUM | 4.4 | Nov 18, 2021 |
| CVE-2021-27022 | A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should… | MEDIUM | 4.9 | Sep 7, 2021 |
| CVE-2021-27019 | PuppetDB logging included potentially sensitive system information. | MEDIUM | 4.3 | Aug 30, 2021 |
| CVE-2021-27020 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. | HIGH | 8.8 | Aug 30, 2021 |
| CVE-2021-27021 | puppet: SQL injection | HIGH | 8.9 | Jul 20, 2021 |
| CVE-2020-7943 | puppet: puppet server and puppetDB may leak sensitive information via metrics API | HIGH | 7.5 | Mar 11, 2020 |
| CVE-2015-5686 | Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an atta… | HIGH | 8.8 | Feb 27, 2020 |
| CVE-2019-10694 | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they… | CRITICAL | 9.8 | Dec 11, 2019 |
| CVE-2013-4968 | Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cros… | MEDIUM | 6.1 | Dec 11, 2019 |
| CVE-2015-1855 | ruby: OpenSSL extension hostname matching implementation violates RFC 6125 | MEDIUM | 5.9 | Nov 29, 2019 |
| CVE-2018-11749 | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet… | CRITICAL | 9.8 | Aug 24, 2018 |
| CVE-2018-6513 | Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x… | HIGH | 8.8 | Jun 11, 2018 |
| CVE-2018-6512 | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise… | CRITICAL | 9.8 | Jun 11, 2018 |
| CVE-2018-6511 | XSS Vulnerability in Puppet Enterprise Console | MEDIUM | 5.4 | May 8, 2018 |
| CVE-2018-6510 | XSS Vulnerability in Puppet Enterprise Console | MEDIUM | 5.4 | May 8, 2018 |
| CVE-2018-6508 | puppet: Unparameterized input in multiple modules can allow a remote user to execute arbitrary code | CRITICAL | 9.0 | Feb 9, 2018 |
| CVE-2017-10690 | puppet: Environment leakage in puppet-agent | MEDIUM | 6.5 | Feb 9, 2018 |
| CVE-2017-10689 | puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions | MEDIUM | 5.5 | Feb 9, 2018 |
Showing 1 to 25 of 89 CVEs