CVE-2023-5214: - Privilege Escalation in Puppet Bolt
Published Oct 6, 2023
·Updated
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
Affected Software
2 affected componentsFixes available
Puppet Bolt<3.27.4
rubygems/bolt<3.27.4
3.27.4
Event History
Oct 6, 2023
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-5214?
The severity of CVE-2023-5214 is critical with a severity score of 9.8.
2
What is the affected software for CVE-2023-5214?
The affected software for CVE-2023-5214 is Puppet Bolt versions prior to 3.27.4.
3
How can I fix CVE-2023-5214?
To fix CVE-2023-5214, you should update Puppet Bolt to version 3.27.4 or newer.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-5214?
The Common Weakness Enumeration (CWE) for CVE-2023-5214 is CWE-269.
5
Where can I find more information about CVE-2023-5214?
You can find more information about CVE-2023-5214 at the following references: [1] [2] [3]