Debian Puppetserver vulnerabilities
2 known vulnerabilities affecting debian/puppetserver.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
LOW2
Vulnerabilities
Page 1 of 1
CVE-2020-7943P2LOWCVSS 7.5PoCfixed in puppetdb 7.11.2-2 (bookworm)2020
CVE-2020-7943 [HIGH] CVE-2020-7943: puppet - Puppet Server and PuppetDB provide useful performance and debugging information ...
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local net
debian
CVE-2023-1894P4LOWCVSS 5.3fixed in puppetserver 7.9.5-2 (bookworm)2023
CVE-2023-1894 [MEDIUM] CVE-2023-1894: puppet - A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Se...
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
Scope: local
bullseye: resolved
debian