CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Puppet 3Puppet Puppet ConnectPuppet EnterpriseJun 17, 2026 Nov 18, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged |
2Fedoraproject Puppet4Fedora PuppetPuppet Agent+1 moreJun 17, 2026 Nov 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. |
1Puppet 2Puppet Puppet EnterpriseJun 17, 2026 Sep 7, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory s...Show more |
1Puppet 3Puppet Puppet EnterprisePuppetdbJun 17, 2026 Jul 20, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query. |
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node...Show more |
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrar...Show more |
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation. |
1Puppet 2Puppet Puppet EnterpriseJun 17, 2026 Jun 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Pupp...Show more |
2Puppet Redhat3Puppet Puppet EnterpriseSatelliteNov 21, 2024 Feb 9, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise...Show more |
3Canonical PuppetRedhat4Puppet Puppet EnterpriseSatellite+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability. |
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet...Show more |
2Debian Puppet2Debian Linux PuppetMay 13, 2026 Jul 5, 2017 N/A· v4 8.2 HIGH· v3 6.0 MEDIUM· v2 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, w...Show more |
1Puppet 3Puppet Puppet AgentPuppet ServerMay 6, 2026 Jun 10, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decod...Show more |
2Puppet Puppetlabs6Facter FacterHiera+3 moreMay 6, 2026 Nov 16, 2014 N/A· v4 N/A· v3 6.2 MEDIUM· v2 Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with...Show more |
Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors. |
2Puppet Puppetlabs3Puppet PuppetPuppet EnterpriseApr 29, 2026 Aug 20, 2013 N/A· v4 N/A· v3 3.6 LOW· v2 Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were us...Show more |
2Puppet Puppetlabs3Puppet PuppetPuppet EnterpriseApr 29, 2026 Aug 20, 2013 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master...Show more |
4Canonical NovellPuppet+1 more6Puppet PuppetPuppet Enterprise+3 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a cra...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated n...Show more |
2Puppet Puppetlabs3Puppet PuppetPuppet EnterpriseApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a repo...Show more |