Puppet Enterprise vulnerabilities

89 known vulnerabilities affecting puppet/puppet_enterprise.

Total CVEs
89
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH18MEDIUM51LOW11

Vulnerabilities

Page 4 of 5
CVE-2013-4964MEDIUMCVSS 5.0≤ 3.0.0v2.5.1+5 more2013-08-20
CVE-2013-4964 [MEDIUM] CWE-264 CVE-2013-4964: Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https sessi Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
nvd
CVE-2013-4955MEDIUMCVSS 5.8≤ 3.0.0v2.5.1+5 more2013-08-20
CVE-2013-4955 [MEDIUM] CWE-20 CVE-2013-4955: Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attack Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the service parameter.
nvd
CVE-2013-4958MEDIUMCVSS 6.9≤ 3.0.0v2.5.1+5 more2013-08-20
CVE-2013-4958 [MEDIUM] CWE-287 CVE-2013-4958: Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers t Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
nvd
CVE-2013-4762MEDIUMCVSS 5.8≤ 3.0.0v2.5.1+5 more2013-08-20
CVE-2013-4762 [MEDIUM] CWE-20 CVE-2013-4762: Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, whic Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions by obtaining an old session ID.
nvd
CVE-2013-4962MEDIUMCVSS 5.8≤ 3.0.0v2.5.1+5 more2013-08-20
CVE-2013-4962 [MEDIUM] CWE-255 CVE-2013-4962: The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current passwo The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.
nvd
CVE-2013-4956LOWCVSS 3.6v2.8.0v2.8.1+2 more2013-08-20
CVE-2013-4956 [LOW] CWE-264 CVE-2013-4956: Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet E Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were used when the modules were originally built, which might allow local users to read or modify those modules depending on the original permi
nvd
CVE-2013-4959LOWCVSS 2.1≤ 3.0.0v2.5.1+5 more2013-08-20
CVE-2013-4959 [LOW] CWE-200 CVE-2013-4959: Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "n Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.
nvd
CVE-2013-3567HIGHCVSS 7.5≤ 2.8.1v1.0+6 more2013-08-19
CVE-2013-3567 [HIGH] CWE-20 CVE-2013-3567: Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
nvd
CVE-2013-2716MEDIUMCVSS 5.0≤ 2.7.2v2.0.0+2 more2013-04-10
CVE-2013-2716 [MEDIUM] CWE-310 CVE-2013-2716: Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client conf Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versions, which allows remote attackers to obtain console access via a crafted cookie.
nvd
CVE-2013-1640CRITICALCVSS 9.0fixed in 1.2.7v2.7.0+1 more2013-03-20
CVE-2013-1640 [CRITICAL] CVE-2013-1640: The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7 The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
nvd
CVE-2013-1655HIGHCVSS 7.5v3.1.02013-03-20
CVE-2013-1655 [HIGH] CWE-20 CVE-2013-1655: Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote a Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."
nvd
CVE-2013-1653HIGHCVSS 7.1v3.1.0v2.7.0+1 more2013-03-20
CVE-2013-1653 [HIGH] CVE-2013-1653: Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2. Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
nvd
CVE-2013-1652MEDIUMCVSS 4.9v3.1.0v2.7.0+1 more2013-03-20
CVE-2013-1652 [MEDIUM] CWE-264 CVE-2013-1652: Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2. Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.
nvd
CVE-2013-1654MEDIUMCVSS 5.0v3.1.02013-03-20
CVE-2013-1654 [MEDIUM] CVE-2013-1654: Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does no Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
nvd
CVE-2013-2274MEDIUMCVSS 6.5v1.2.02013-03-20
CVE-2013-2274 [MEDIUM] CVE-2013-2274: Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated user Puppet 2.6.x before 2.6.18 and Puppet Enterprise 1.2.x before 1.2.7 allows remote authenticated users to execute arbitrary code on the puppet master, or an agent with puppet kick enabled, via a crafted request for a report.
nvd
CVE-2013-2275MEDIUMCVSS 4.0v3.1.0v2.7.0+1 more2013-03-20
CVE-2013-2275 [MEDIUM] CVE-2013-2275: The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated nodes to submit reports for other nodes via unspecified vectors.
nvd
CVE-2012-3867MEDIUMCVSS 4.3≤ 2.5.12012-08-06
CVE-2012-3867 [MEDIUM] CWE-264 CVE-2012-3867: lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate
nvd
CVE-2012-3864MEDIUMCVSS 4.0≤ 2.5.12012-08-06
CVE-2012-3864 [MEDIUM] CWE-200 CVE-2012-3864: Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote auth Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.
nvd
CVE-2012-3408LOWCVSS 2.6fixed in 2.5.22012-08-06
CVE-2012-3408 [LOW] CWE-287 CVE-2012-3408: lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, support lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an agent by acquiring a previously used IP address.
nvd
CVE-2012-3866LOWCVSS 2.1≤ 2.5.12012-08-06
CVE-2012-3866 [LOW] CWE-264 CVE-2012-3866: lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
nvd