Puppetlabs / Puppet
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2013-1399 | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in t… | MEDIUM | 6.8 | Mar 14, 2014 |
| CVE-2013-1398 | The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authen… | HIGH | 8.5 | Mar 14, 2014 |
| CVE-2012-5158 | Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retai… | MEDIUM | 4.0 | Mar 14, 2014 |
| CVE-2013-4969 | Puppet: Unsafe use of Temp files in File type | LOW | 2.1 | Jan 7, 2014 |
| CVE-2013-4956 | Puppet: Local Privilege Escalation/Arbitrary Code Execution | LOW | 3.6 | Aug 20, 2013 |
| CVE-2013-4761 | Puppet: resource_type service code execution | MEDIUM | 5.1 | Aug 20, 2013 |
| CVE-2013-3567 | puppet: remote code execution on master from unauthenticated clients | HIGH | 7.5 | Aug 19, 2013 |
| CVE-2013-2716 | Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1… | MEDIUM | 5.0 | Apr 10, 2013 |
| CVE-2013-2275 | Puppet: default auth.conf allows authenticated node to submit a report for any other node | MEDIUM | 4.0 | Mar 20, 2013 |
| CVE-2013-2274 | Puppet: HTTP PUT report saving code execution vulnerability | MEDIUM | 6.5 | Mar 20, 2013 |
| CVE-2013-1655 | Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "… | HIGH | 7.5 | Mar 20, 2013 |
| CVE-2013-1654 | Puppet: SSL protocol downgrade | MEDIUM | 5.0 | Mar 20, 2013 |
| CVE-2013-1653 | Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming conne… | HIGH | 7.1 | Mar 20, 2013 |
| CVE-2013-1652 | Puppet: HTTP GET request catalog retrieval | MEDIUM | 4.9 | Mar 20, 2013 |
| CVE-2012-3867 | puppet: insufficient validation of agent names in CN of SSL certificate requests | MEDIUM | 4.3 | Aug 6, 2012 |
| CVE-2012-3866 | lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local us… | LOW | 2.1 | Aug 6, 2012 |
| CVE-2012-3865 | puppet: authenticated clients allowed to delete arbitrary files on the puppet master | LOW | 3.5 | Aug 6, 2012 |
| CVE-2012-3864 | puppet: authenticated clients allowed to read arbitrary files from the puppet master | MEDIUM | 4.0 | Aug 6, 2012 |
| CVE-2012-3408 | puppet: possible host impersonation when using certificates issues for IP address | LOW | 2.6 | Aug 6, 2012 |
| CVE-2012-1989 | puppet: Insecure temporary file use for NET::Telnet connection log (/tmp/out.log) | LOW | 3.6 | Jun 27, 2012 |
| CVE-2012-1986 | puppet: Filebucket arbitrary file read | LOW | 2.1 | May 29, 2012 |
| CVE-2012-1906 | puppet: Puppet uses predictable filenames, allowing arbitrary file overwrite | MEDIUM | 5.5 | May 29, 2012 |
| CVE-2012-1054 | Puppet 2.6.13 Klogin File Handling Issue | MEDIUM | 4.4 | May 29, 2012 |
| CVE-2012-1053 | Puppet 2.6.13 group ID handling issues | MEDIUM | 6.9 | May 29, 2012 |
| CVE-2011-3872 | puppet: MITM by the x509v3 certificate signing | LOW | 2.6 | Oct 27, 2011 |
Showing 1 to 25 of 29 CVEs