First published: Fri Oct 06 2023(Updated: )
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
Credit: security@puppet.com security@puppet.com security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Bolt | <3.27.4 | |
rubygems/bolt | <3.27.4 | 3.27.4 |
<3.27.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5214 is critical with a severity score of 9.8.
The affected software for CVE-2023-5214 is Puppet Bolt versions prior to 3.27.4.
To fix CVE-2023-5214, you should update Puppet Bolt to version 3.27.4 or newer.
The Common Weakness Enumeration (CWE) for CVE-2023-5214 is CWE-269.
You can find more information about CVE-2023-5214 at the following references: [1] [2] [3]