Skip to main content

Vendor archive

puppetlabs CVEs

Beta · best-effort

34 CVEs tagged to vendor puppetlabs0 Critical, 4 High, 20 Medium, 10 Low, 0 Unrated.

CVE-2015-7331

Published Jan 30, 2017

The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1426

Published Feb 23, 2015

Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1399

Published Mar 14, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5158

Published Mar 14, 2014

Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspeci…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2716

Published Apr 10, 2013

Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 34 CVEsPage 1 of 2