Filter
AND
-Infinity
0

PuppetDeserialization of untrusted data

First published (updated )

redhat/puppet-serverA Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certifica…

First published (updated )

Puppet EnterprisePuppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https sessi…

First published (updated )

Puppet EnterpriseInput Validation

First published (updated )

redhat/puppetLast updated 24 July 2024

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Puppet EnterprisePuppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors r…

First published (updated )

Puppet EnterpriseXSS Vulnerability in Puppet Enterprise Console

First published (updated )

Puppet EnterprisePuppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a…

First published (updated )

Puppet MCollective SSHKey Security PuppetInput Validation

First published (updated )

Puppet EnterpriseXSS Vulnerability in Puppet Enterprise Console

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Puppet EnterpriseVersions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuratio…

First published (updated )

Puppet EnterpriseInfoleak

First published (updated )

PuppetPuppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary…

First published (updated )

PuppetPuppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissi…

First published (updated )

PuppetPuppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a pred…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PuppetPath Traversal

First published (updated )

PuppetPuppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote …

First published (updated )

Puppet EnterprisePuppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret ha…

First published (updated )

PuppetInfoleak

First published (updated )

PuppetInput Validation

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PuppetCommand Injection, OS Command Injection

First published (updated )

Puppet DashboardXSS

First published (updated )

Puppet EnterpriseCode Injection

First published (updated )

Puppet EnterprisePuppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, w…

First published (updated )

Puppet EnterpriseThe master external node classification script in Puppet Enterprise before 3.2.0 does not verify the…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Puppet EnterpriseCSRF

First published (updated )

Puppet EnterprisePuppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers t…

First published (updated )

Puppet EnterpriseThe reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current passwo…

First published (updated )

Puppet EnterpriseXSS

First published (updated )

Puppet EnterpriseInput Validation

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203