cbcvebase.

Debian Puppet vulnerabilities

40 known vulnerabilities affecting debian/puppet.

Total CVEs
40
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM15LOW18

Vulnerabilities

Page 1 of 2
CVE-2020-7943P2LOWCVSS 7.5PoCfixed in puppetdb 7.11.2-2 (bookworm)2020
CVE-2020-7943 [HIGH] CVE-2020-7943: puppet - Puppet Server and PuppetDB provide useful performance and debugging information ... Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local net
debian
CVE-2013-1640P3CRITICALCVSS 9.0fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1640 [CRITICAL] CVE-2013-1640: puppet - The (1) template and (2) inline_template functions in the master server in Puppe... The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request. Scope: local bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2016-5713P3CRITICALCVSS 9.8fixed in puppet 4.7.0-1 (bullseye)2016
CVE-2016-5713 [CRITICAL] CVE-2016-5713: puppet - Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Executi... Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0. Scope: local bullseye: resolved (fixed in 4.7.0-1)
debian
CVE-2013-3567P3HIGHCVSS 7.5fixed in puppet 3.2.2-1 (bullseye)2013
CVE-2013-3567 [HIGH] CVE-2013-3567: puppet - Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before ... Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call. Scope: local bullseye: resolved (fixed in 3.2.2-1)
debian
CVE-2017-2295P3HIGHCVSS 8.2fixed in puppet 4.8.2-5 (bullseye)2017
CVE-2017-2295 [HIGH] CVE-2017-2295: puppet - Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the ... Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML. Scope: local bullseye:
debian
CVE-2016-5714P3HIGHCVSS 7.2fixed in puppet 4.8.0-1 (bullseye)2016
CVE-2016-5714 [HIGH] CVE-2016-5714: puppet - Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 th... Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability." Scope: local bullseye: resolved (fixed i
debian
CVE-2013-1655P3HIGHCVSS 7.5fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1655 [HIGH] CVE-2013-1655: puppet - Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or la... Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes." Scope: local bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-1653P3HIGHCVSS 7.1fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1653 [HIGH] CVE-2013-1653: puppet - Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet En... Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request. Scope: local bullseye: resolved (fixed in 2.7.1
debian
CVE-2013-2274P3MEDIUMCVSS 6.5fixed in puppet 2.7-1 (bullseye)2013
CVE-2013-2274 [MEDIUM] CVE-2013-2274: puppet - Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remot... Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report. Scope: local bullseye: resolved (fixed in 2.7-1)
debian
CVE-2012-1988P4MEDIUMCVSS 6.0fixed in puppet 2.7.13-1 (bullseye)2012
CVE-2012-1988 [MEDIUM] CVE-2012-1988: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U... Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket req
debian
CVE-2013-4761P4LOWCVSS 5.1fixed in puppet 3.2.4-1 (bullseye)2013
CVE-2013-4761 [MEDIUM] CVE-2013-4761: puppet - Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, ... Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.
debian
CVE-2014-3250P4LOWCVSS 6.5fixed in puppet 3.7.0-1 (bullseye)2014
CVE-2014-3250 [MEDIUM] CVE-2014-3250: puppet - The default vhost configuration file in Puppet before 3.6.2 does not include the... The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4. Scope: local bullseye: resolved (fixed in 3.7.0-1)
debian
CVE-2011-0528P4MEDIUMCVSS 5.5fixed in puppet 2.6.2-3 (bullseye)2011
CVE-2011-0528 [MEDIUM] CVE-2011-0528: puppet - Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, ... Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors. Scope: local bullseye: resolved (fixed in 2.6.2-3)
debian
CVE-2011-3848P4MEDIUMCVSS 5.0fixed in puppet 2.7.3-2 (bullseye)2011
CVE-2011-3848 [MEDIUM] CVE-2011-3848: puppet - Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before... Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25. Scope: local bullseye: resolved (fixed in 2.7.3-2)
debian
CVE-2013-1654P4MEDIUMCVSS 5.0fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1654 [MEDIUM] CVE-2013-1654: puppet - Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x b... Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors. Scope: local bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-1652P4MEDIUMCVSS 4.9fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1652 [MEDIUM] CVE-2013-1652: puppet - Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet En... Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors. Scope: local bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2012-1053P4MEDIUMCVSS 6.9fixed in puppet 2.7.11-1 (bullseye)2012
CVE-2012-1053 [MEDIUM] CVE-2012-1053: puppet - The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Pu... The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in cer
debian
CVE-2023-1894P4LOWCVSS 5.3fixed in puppetserver 7.9.5-2 (bookworm)2023
CVE-2023-1894 [MEDIUM] CVE-2023-1894: puppet - A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Se... A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. Scope: local bullseye: resolved
debian
CVE-2012-3864P4MEDIUMCVSS 4.0fixed in puppet 2.7.18-1 (bullseye)2012
CVE-2012-3864 [MEDIUM] CVE-2012-3864: puppet - Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2... Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request. Scope: local bullseye: resolved (fixed in 2.7.18-1)
debian
CVE-2014-3248P4LOWCVSS 6.2fixed in facter 2.0.1-1 (bookworm)2014
CVE-2014-3248 [MEDIUM] CVE-2014-3248: facter - Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppe... Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rub
debian
Debian Puppet vulnerabilities | cvebase