RSS   Vulnerabilities for 'Puppet server'   RSS

2021-11-18
 
CVE-2021-27023

NVD-CWE-noinfo
 

 
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

 
2020-03-11
 
CVE-2020-7943

CWE-200
 

 
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.4.0, Puppet Server 6.9.1 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects Puppet Enterprise 2018.1.x stream prior to 2018.1.13, and prior to 2019.4.0; Puppet Server prior to 6.9.1, and prior to 5.3.12; PuppetDB prior to 6.9.1, and prior to 5.2.13.

 
2019-12-16
 
CVE-2018-11751

CWE-295
 

 
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

 
2014-12-17
 
CVE-2014-7170

CWE-362
 

 
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

 

 >>> Vendor: Puppet 19 Products
Puppet
Mcollective
Enterprise
Puppetlabs-apache
Chloride
Puppet enterprise
Puppet dashboard
Hiera
Marionette collective
Puppet server
Stdlib
Facter
Discovery
Puppet agent
Continuous delivery
Puppetdb
Remediate
Puppet connect
Firewall


Copyright 2024, cxsecurity.com

 

Back to Top