Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 80 results


CVE-2021-27018

Medium priority
Needs evaluation

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are...

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-27021

Medium priority
Vulnerable

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

1 affected packages

puppetdb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppetdb Not affected Vulnerable Not in release Not in release Ignored
Show less packages

CVE-2021-27017

Medium priority
Not affected

[Unknown description]

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not affected Not affected Not affected
Show less packages

CVE-2020-7943

Medium priority
Needs evaluation

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined...

2 affected packages

puppet, puppetdb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
puppetdb Needs evaluation Needs evaluation Not in release Not in release Not in release
Show less packages

CVE-2020-7942

Medium priority
Not affected

Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog...

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not affected Not affected
Show less packages

CVE-2018-11751

Medium priority
Ignored

Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not affected Not affected
Show less packages

CVE-2013-4968

Medium priority
Not affected

Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live...

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet
Show less packages

CVE-2018-11749

Medium priority
Not affected

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet...

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not affected Not affected
Show less packages

CVE-2018-6516

Negligible priority
Ignored

On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code...

1 affected packages

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet Not affected Not affected
Show less packages

CVE-2016-9590

Low priority

Some fixes available 1 of 5

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying...

1 affected packages

puppet-module-swift

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
puppet-module-swift Not affected Not affected Not affected Fixed Vulnerable
Show less packages