Skip to main content

Vendor archive

puppet CVEs

Beta · best-effort

128 CVEs tagged to vendor puppet14 Critical, 31 High, 69 Medium, 14 Low, 0 Unrated.

CVE-2025-5459

Published Jun 26, 2025

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterp…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5309

Published Nov 7, 2023

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5214

Published Oct 6, 2023

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2530

Published Jun 7, 2023

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-3276

Published Oct 7, 2022

Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsa…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0675

Published Mar 2, 2022

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unma…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27024

Published Nov 18, 2021

A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This is…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27022

Published Sep 7, 2021

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27018

Published Aug 30, 2021

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly vali…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7945

Published Sep 18, 2020

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is res…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7944

Published Mar 26, 2020

In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5686

Published Feb 27, 2020

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7942

Published Feb 19, 2020

Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to ever…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11751

Published Dec 16, 2019

Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 128 CVEsPage 1 of 6