Search CVE reports


Toggle filters

11 – 20 of 80 results


CVE-2021-27019

Medium priority
Needs evaluation

PuppetDB logging included potentially sensitive system information.

1 affected package

puppetdb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppetdb Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-27018

Medium priority
Needs evaluation

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are...

1 affected package

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-27017

Medium priority
Not affected

Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

1 affected package

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not affected Not affected
Show less packages

CVE-2020-7943

Medium priority
Needs evaluation

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined...

2 affected packages

puppet, puppetdb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not in release Needs evaluation Needs evaluation Needs evaluation
puppetdb Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2020-7942

Medium priority
Not affected

Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog...

1 affected package

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not affected
Show less packages

CVE-2018-6516

Negligible priority
Ignored

On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code...

1 affected package

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not affected
Show less packages

CVE-2018-6508

Medium priority
Needs evaluation

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected...

3 affected packages

puppet-module-puppetlabs-apache, puppet-module-puppetlabs-apt, puppet-module-puppetlabs-mysql

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet-module-puppetlabs-apache Needs evaluation Needs evaluation Needs evaluation Needs evaluation
puppet-module-puppetlabs-apt Needs evaluation Needs evaluation Needs evaluation Needs evaluation
puppet-module-puppetlabs-mysql Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-11751

Medium priority
Ignored

Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

1 affected package

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not affected
Show less packages

CVE-2018-11749

Medium priority
Not affected

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet...

1 affected package

puppet

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet Not affected
Show less packages

CVE-2017-2299

Medium priority
Vulnerable

Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir` parameter, a default will be...

1 affected package

puppet-module-puppetlabs-apache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet-module-puppetlabs-apache Not affected Not affected Not affected Not affected
Show less packages