Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 1.3% | — | Puppet EnterpriseAI | 11/9/2026 | 18/9/2026 | Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization.… | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | Puppet Resource APIAIPuppet CoreAIPuppet EnterpriseAI | 3/7/2026 | 6/7/2026 | Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api… | |
| Aplazada | Media (6.9) | 0.19% | — | Puppet EnterpriseAI | 24/9/2025 | 25/9/2026 | In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license and has enabled the Infra Assistant… | |
| Modificada | Alta (8.6) | 1.1% | — | Puppet Enterprise | 26/6/2025 | 4/9/2026 | A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0. | |
| Modificada | Crítica (9.8) | 0.50% | — | Puppet Enterprise | 7/11/2023 | 17/6/2026 | Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations. | |
| Modificada | Alta (7.5) | 0.48% | — | Puppet EnterprisePuppet Server | 3/10/2023 | 17/6/2026 | For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked. | |
| Modificada | Crítica (9.8) | 1.1% | — | Puppet Enterprise | 7/6/2023 | 17/6/2026 | A privilege escalation allowing remote code execution was discovered in the orchestration service. | |
| Modificada | Media (5.3) | 0.44% | — | Puppet EnterprisePuppet Server | 4/5/2023 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. | |
| Modificada | Media (4.4) | 0.25% | — | PuppetPuppet ConnectPuppet Enterprise | 18/11/2021 | 17/6/2026 | A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged | |
| Modificada | Media (6.5) | 1.1% | — | PuppetPuppet AgentPuppet EnterpriseFedoraproject Fedora | 18/11/2021 | 17/6/2026 | A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. | |
| Modificada | Crítica (9.8) | 1.4% | — | Puppet AgentPuppet EnterprisePuppet ServerFedoraproject Fedora | 18/11/2021 | 17/6/2026 | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007 | |
| Modificada | Media (4.9) | 0.92% | — | PuppetPuppet Enterprise | 7/9/2021 | 17/6/2026 | A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes). | |
| Modificada | Alta (8.8) | 1.1% | — | Puppet Enterprise | 30/8/2021 | 17/6/2026 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. | |
| Modificada | Media (4.3) | 0.74% | — | Puppet EnterprisePuppetdb | 30/8/2021 | 17/6/2026 | PuppetDB logging included potentially sensitive system information. | |
| Modificada | Alta (8.8) | 1.3% | — | PuppetPuppet EnterprisePuppetdb | 20/7/2021 | 17/6/2026 | A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query. | |
| Modificada | Alta (7.5) | 7.9% | — | Puppet EnterprisePuppet ServerPuppetdb | 11/3/2020 | 17/6/2026 | Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names.… | |
| Modificada | Alta (8.8) | 0.45% | — | Puppet Enterprise | 27/2/2020 | 17/6/2026 | Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session. | |
| Modificada | Crítica (9.8) | 1.1% | — | Puppet Enterprise | 12/12/2019 | 17/6/2026 | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9. | |
| Modificada | Media (6.1) | 0.82% | — | Puppet Enterprise | 11/12/2019 | 16/6/2026 | Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management." | |
| Modificada | Media (5.9) | 2.8% | — | Ruby-lang RubyRuby-lang TrunkDebian LinuxPuppet Agent+1 | 29/11/2019 | 17/6/2026 | verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and… | |
| Modificada | Crítica (9.9) | 1.9% | — | Jenkins Puppet Enterprise Pipeline | 16/10/2019 | 17/6/2026 | Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.76% | — | Puppet Enterprise | 24/8/2018 | 17/6/2026 | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score. | |
| Modificada | Alta (7.8) | 0.85% | — | Puppet Enterprise Client Tools | 14/6/2018 | 17/6/2026 | On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation. | |
| Modificada | Alta (8.8) | 1.1% | — | PuppetPuppet Enterprise | 11/6/2018 | 17/6/2026 | Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows… | |
| Modificada | Crítica (9.8) | 1.9% | — | Puppet Pe-razor-serverPuppet EnterprisePuppet Razor-server | 11/6/2018 | 17/6/2026 | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0. |