Debian Puppet vulnerabilities
90 known vulnerabilities affecting debian/puppet.
Total CVEs
90
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM16LOW66
Vulnerabilities
Page 3 of 5
CVE-2014-3248LOWCVSS 6.2fixed in facter 2.0.1-1 (bookworm)2014
CVE-2014-3248 [MEDIUM] CVE-2014-3248: facter - Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppe...
Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rub
debian
CVE-2013-1640CRITICALCVSS 9.0fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1640 [CRITICAL] CVE-2013-1640: puppet - The (1) template and (2) inline_template functions in the master server in Puppe...
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
Scope: local
bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-1655HIGHCVSS 7.5fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1655 [HIGH] CVE-2013-1655: puppet - Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or la...
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."
Scope: local
bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-3567HIGHCVSS 7.5fixed in puppet 3.2.2-1 (bullseye)2013
CVE-2013-3567 [HIGH] CVE-2013-3567: puppet - Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before ...
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
Scope: local
bullseye: resolved (fixed in 3.2.2-1)
debian
CVE-2013-1653HIGHCVSS 7.1fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1653 [HIGH] CVE-2013-1653: puppet - Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet En...
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
Scope: local
bullseye: resolved (fixed in 2.7.1
debian
CVE-2013-2275MEDIUMCVSS 4.0fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-2275 [MEDIUM] CVE-2013-2275: puppet - The default configuration for puppet masters 0.25.0 and later in Puppet before 2...
The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated nodes to submit reports for other nodes via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-2274MEDIUMCVSS 6.5fixed in puppet 2.7-1 (bullseye)2013
CVE-2013-2274 [MEDIUM] CVE-2013-2274: puppet - Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remot...
Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.
Scope: local
bullseye: resolved (fixed in 2.7-1)
debian
CVE-2013-1652MEDIUMCVSS 4.9fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1652 [MEDIUM] CVE-2013-1652: puppet - Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet En...
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-1654MEDIUMCVSS 5.0fixed in puppet 2.7.18-3 (bullseye)2013
CVE-2013-1654 [MEDIUM] CVE-2013-1654: puppet - Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x b...
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 2.7.18-3)
debian
CVE-2013-4965LOWCVSS 5.02013
CVE-2013-4965 [MEDIUM] CVE-2013-4965: puppet - Puppet Enterprise before 3.1.0 does not properly restrict the number of authenti...
Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force attack.
Scope: local
bullseye: resolved
debian
CVE-2013-4963LOWCVSS 6.82013
CVE-2013-4963 [MEDIUM] CVE-2013-4963: puppet - Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise ...
Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.
Scope: local
bullseye: resolved
debian
CVE-2013-1398LOWCVSS 8.52013
CVE-2013-1398 [HIGH] CVE-2013-1398: puppet - The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not proper...
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.
Scope: local
bullseye: resolved
debian
CVE-2013-4959LOWCVSS 2.12013
CVE-2013-4959 [LOW] CVE-2013-4959: puppet - Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive inform...
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.
Scope: local
bullseye: resolved
debian
CVE-2013-4967LOWCVSS 5.02013
CVE-2013-4967 [MEDIUM] CVE-2013-4967: puppet - Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database pa...
Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes.
Scope: local
bullseye: resolved
debian
CVE-2013-4956LOWCVSS 3.6fixed in puppet 3.2.4-1 (bullseye)2013
CVE-2013-4956 [LOW] CVE-2013-4956: puppet - Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before...
Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were used when the modules were originally built, which might allow local users to read or modify those modules depending on the original permissions.
Scope: l
debian
CVE-2013-4955LOWCVSS 5.82013
CVE-2013-4955 [MEDIUM] CVE-2013-4955: puppet - Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 ...
Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the service parameter.
Scope: local
bullseye: resolved
debian
CVE-2013-4761LOWCVSS 5.1fixed in puppet 3.2.4-1 (bullseye)2013
CVE-2013-4761 [MEDIUM] CVE-2013-4761: puppet - Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, ...
Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service. NOTE: this vulnerability can only be exploited utilizing unspecified "local file system access" to the Puppet Master.
debian
CVE-2013-4969LOWCVSS 2.1fixed in puppet 3.4.1-1 (bullseye)2013
CVE-2013-4969 [LOW] CVE-2013-4969: puppet - Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4...
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Scope: local
bullseye: resolved (fixed in 3.4.1-1)
debian
CVE-2013-4966LOWCVSS 6.42013
CVE-2013-4966 [MEDIUM] CVE-2013-4966: puppet - The master external node classification script in Puppet Enterprise before 3.2.0...
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.
Scope: local
bullseye: resolved
debian
CVE-2013-4961LOWCVSS 5.02013
CVE-2013-4961 [MEDIUM] CVE-2013-4961: puppet - Puppet Enterprise before 3.0.1 includes version information for the Apache and P...
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
Scope: local
bullseye: resolved
debian