cbcvebase.
CVE-2014-9355
published 2014-12-19

CVE-2014-9355: Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request information by leveraging access to an…

PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.61%
47.0th percentile
Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request information by leveraging access to an unspecified API endpoint.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianpuppet
puppetpuppet_enterprise<= 3.7.0

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_debian4.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.