cbcvebase.

Debian Puppet vulnerabilities

90 known vulnerabilities affecting debian/puppet.

Total CVEs
90
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM16LOW66

Vulnerabilities

Page 4 of 5
CVE-2013-4964LOWCVSS 5.02013
CVE-2013-4964 [MEDIUM] CVE-2013-4964: puppet - Puppet Enterprise before 3.0.1 does not set the secure flag for the session cook... Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. Scope: local bullseye: resolved
debian
CVE-2013-1399LOWCVSS 6.82013
CVE-2013-1399 [MEDIUM] CVE-2013-1399: puppet - Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node reque... Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet Enterprise (PE) before 2.7.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. Scope: local bullseye: resolved
debian
CVE-2013-4962LOWCVSS 5.82013
CVE-2013-4962 [MEDIUM] CVE-2013-4962: puppet - The reset password page in Puppet Enterprise before 3.0.1 does not force entry o... The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors. Scope: local bullseye: resolved
debian
CVE-2013-4958LOWCVSS 6.92013
CVE-2013-4958 [MEDIUM] CVE-2013-4958: puppet - Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it ea... Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation. Scope: local bullseye: resolved
debian
CVE-2013-4073LOWCVSS 5.92013
CVE-2013-4073 [MEDIUM] CVE-2013-4073: puppet - The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in R... The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certi
debian
CVE-2013-4971LOWCVSS 5.02013
CVE-2013-4971 [MEDIUM] CVE-2013-4971: puppet - Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoin... Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors. Scope: local bullseye: resolved
debian
CVE-2013-4762LOWCVSS 5.82013
CVE-2013-4762 [MEDIUM] CVE-2013-4762: puppet - Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a... Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions by obtaining an old session ID. Scope: local bullseye: resolved
debian
CVE-2013-4968LOWCVSS 6.12013
CVE-2013-4968 [MEDIUM] CVE-2013-4968: puppet - Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacki... Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management." Scope: local bullseye: resolved
debian
CVE-2012-3864MEDIUMCVSS 4.0fixed in puppet 2.7.18-1 (bullseye)2012
CVE-2012-3864 [MEDIUM] CVE-2012-3864: puppet - Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2... Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request. Scope: local bullseye: resolved (fixed in 2.7.18-1)
debian
CVE-2012-1053MEDIUMCVSS 6.9fixed in puppet 2.7.11-1 (bullseye)2012
CVE-2012-1053 [MEDIUM] CVE-2012-1053: puppet - The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Pu... The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in cer
debian
CVE-2012-1054MEDIUMCVSS 4.4fixed in puppet 2.7.11-1 (bullseye)2012
CVE-2012-1054 [MEDIUM] CVE-2012-1054: puppet - Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) U... Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login. Scope: local bullseye: resolved (fixed in 2.7.11-1)
debian
CVE-2012-1988MEDIUMCVSS 6.0fixed in puppet 2.7.13-1 (bullseye)2012
CVE-2012-1988 [MEDIUM] CVE-2012-1988: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U... Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket req
debian
CVE-2012-3867MEDIUMCVSS 4.3fixed in puppet 2.7.18-1 (bullseye)2012
CVE-2012-3867 [MEDIUM] CVE-2012-3867: puppet - lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before... lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI contro
debian
CVE-2012-1906LOWCVSS 3.3fixed in puppet 2.7.13-1 (bullseye)2012
CVE-2012-1906 [LOW] CVE-2012-1906: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U... Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp. Scope: local bullseye:
debian
CVE-2012-3408LOWCVSS 2.6fixed in puppet 2.7.18-1 (bullseye)2012
CVE-2012-3408 [LOW] CVE-2012-3408: puppet - lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise b... lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an agent by acquiring a previously used IP address. Scope: local bullseye: resolved (fixed in 2.7.18-1)
debian
CVE-2012-3866LOWCVSS 2.1fixed in puppet 2.7.18-1 (bullseye)2012
CVE-2012-3866 [LOW] CVE-2012-3866: puppet - lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise befo... lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file. Scope: local bullseye: resolved (fixed in 2.7.18-1)
debian
CVE-2012-1986LOWCVSS 2.1fixed in puppet 2.7.13-1 (bullseye)2012
CVE-2012-1986 [LOW] CVE-2012-1986: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U... Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket. Scope: local bulls
debian
CVE-2012-6120LOWCVSS 2.1fixed in puppet 2.6.4-2 (bullseye)2012
CVE-2012-6120 [LOW] CVE-2012-6120: puppet - Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with wo... Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files. Scope: local bullseye: resolved (fixed in 2.6.4-2)
debian
CVE-2012-1987LOWCVSS 2.1fixed in puppet 2.7.13-1 (bullseye)2012
CVE-2012-1987 [LOW] CVE-2012-1987: puppet - Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13,... Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /d
debian
CVE-2012-3865LOWCVSS 3.5fixed in puppet 2.7.18-1 (bullseye)2012
CVE-2012-3865 [LOW] CVE-2012-3865: puppet - Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet befor... Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name. Scope: local bullseye: resolved (fixed in 2.7.18-1)
debian