CVEs (29)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Puppet Puppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 May 29, 2012 N/A· v4 N/A· v3 2.1 LOW· v2 Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on...Show more |
2Puppet Puppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 May 29, 2012 N/A· v4 N/A· v3 3.3 LOW· v2 Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, whic...Show more |
2Puppet Puppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 May 29, 2012 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privile...Show more |
2Puppet Puppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 May 29, 2012 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly man...Show more |
2Puppet Puppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Oct 27, 2011 N/A· v4 N/A· v3 2.6 LOW· v2 Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alt...Show more |
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files. |
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file. |
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file. |
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key paramete...Show more |