Search CVE reports
11 – 20 of 80 results
CVE-2021-27018
Medium priorityThe mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are...
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2021-27021
Medium priorityA flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
1 affected packages
puppetdb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppetdb | Not affected | Vulnerable | Not in release | Not in release | Ignored |
CVE-2021-27017
Medium priority[Unknown description]
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | — | — | Not affected | Not affected | Not affected |
CVE-2020-7943
Medium priorityPuppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined...
2 affected packages
puppet, puppetdb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
puppetdb | Needs evaluation | Needs evaluation | Not in release | Not in release | Not in release |
CVE-2020-7942
Medium priorityPreviously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog...
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | — | — | — | Not affected | Not affected |
CVE-2018-11751
Medium priorityPrevious versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | — | — | — | Not affected | Not affected |
CVE-2013-4968
Medium priorityPuppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live...
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | — | — | — | — | — |
CVE-2018-11749
Medium priorityWhen users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet...
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | — | — | — | Not affected | Not affected |
CVE-2018-6516
Negligible priorityOn Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code...
1 affected packages
puppet
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet | — | — | — | Not affected | Not affected |
CVE-2016-9590
Low prioritySome fixes available 1 of 5
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying...
1 affected packages
puppet-module-swift
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
puppet-module-swift | Not affected | Not affected | Not affected | Fixed | Vulnerable |