← Back

Puppet

puppet

128 CVEs • 28 products

Products (28)

Click to collapse
Toggle
Puppet
puppet
Puppet Agent
puppet_agent
Puppet Server
puppet_server
Puppetdb
puppetdb
Facter
facter
Discovery
discovery
Hiera
hiera
Stdlib
stdlib
Mcollective
mcollective
Razor Server
razor-server
Device Manager
device_manager
Cisco Ios
cisco_ios
Chloride
chloride
Remediate
remediate
Puppet Connect
puppet_connect
Firewall
firewall
Bolt
bolt

CVEs (128)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Puppet
Puppetlabs
4Puppet
PuppetPuppet Enterprise+1 more
Apr 29, 2026
May 29, 2012
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privile...Show more
Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.Show less
2Puppet
Puppetlabs
4Puppet
PuppetPuppet Enterprise+1 more
Apr 29, 2026
May 29, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly man...Show more
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.Show less
2Puppet
Puppetlabs
4Puppet
PuppetPuppet Enterprise+1 more
Apr 29, 2026
Oct 27, 2011
N/A· v4
N/A· v3
2.6 LOW· v2
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alt...Show more
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."Show less
2Puppet
Puppetlabs
2Puppet
Puppet
Apr 29, 2026
Oct 27, 2011
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
2Puppet
Puppetlabs
2Puppet
Puppet
Apr 29, 2026
Oct 27, 2011
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
2Puppet
Puppetlabs
2Puppet
Puppet
Apr 29, 2026
Oct 27, 2011
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
2Puppet
Puppetlabs
2Puppet
Puppet
Apr 29, 2026
Oct 27, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key paramete...Show more
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.Show less
1Puppet
1Puppet
Apr 29, 2026
Mar 3, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.a...Show more
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.Show less