Skip to main content

Vendor/product archive

puppet / puppet_enterprise CVEs

Beta · best-effort

90 CVEs tagged to puppet / puppet_enterprise8 Critical, 17 High, 54 Medium, 11 Low, 0 Unrated.

CVE-2025-5459

Published Jun 26, 2025

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterp…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5309

Published Nov 7, 2023

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2530

Published Jun 7, 2023

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27022

Published Sep 7, 2021

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5686

Published Feb 27, 2020

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10694

Published Dec 12, 2019

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4968

Published Dec 11, 2019

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XS…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11749

Published Aug 24, 2018

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6513

Published Jun 11, 2018

Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Pu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6511

Published May 8, 2018

A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Ent…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6510

Published May 8, 2018

A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrat…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6508

Published Feb 9, 2018

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vu…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 90 CVEsPage 1 of 4