Puppetlabs Puppet vulnerabilities

29 known vulnerabilities affecting puppetlabs/puppet.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM16LOW9

Vulnerabilities

Page 2 of 2
CVE-2012-1054MEDIUMCVSS 4.4v2.7.0v2.7.12012-05-29
CVE-2012-1054 [MEDIUM] CWE-264 CVE-2012-1054: Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.
nvd
CVE-2012-1053MEDIUMCVSS 6.9v2.7.0v2.7.12012-05-29
CVE-2012-1053 [MEDIUM] CWE-264 CVE-2012-1053: The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2. The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementa
nvd
CVE-2012-1906LOWCVSS 3.3v2.7.0v2.7.12012-05-29
CVE-2012-1906 [LOW] CWE-264 CVE-2012-1906: Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
nvd
CVE-2012-1986LOWCVSS 2.1v2.7.0v2.7.12012-05-29
CVE-2012-1986 [LOW] CWE-264 CVE-2012-1986: Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
nvd
CVE-2011-3869MEDIUMCVSS 6.3v2.7.0v2.7.12011-10-27
CVE-2011-3869 [MEDIUM] CWE-59 CVE-2011-3869: Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
nvd
CVE-2011-3871MEDIUMCVSS 6.2v2.7.0v2.7.12011-10-27
CVE-2011-3871 [MEDIUM] CWE-264 CVE-2011-3871: Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a pred Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.
nvd
CVE-2011-3848MEDIUMCVSS 5.0v2.7.0v2.7.12011-10-27
CVE-2011-3848 [MEDIUM] CWE-22 CVE-2011-3848: Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
nvd
CVE-2011-3870MEDIUMCVSS 6.3v2.7.0v2.7.12011-10-27
CVE-2011-3870 [MEDIUM] CWE-59 CVE-2011-3870: Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissi Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
nvd
CVE-2011-3872LOWCVSS 2.6v2.7.0v2.7.12011-10-27
CVE-2011-3872 [LOW] CWE-20 CVE-2011-3872: Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1. Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack agai
nvd