Puppet
Puppet Enterprise: vulnerabilidades y CVE
Puppet Enterprise tiene 92 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE92
Últimos 12 meses2
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85979 | Alta (8.6) | 1.3% | — | 11 sept 2026 | Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value… |
| CVE-2026-8804 | Media (6.7) | 0.11% | — | 3 jul 2026 | Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored… |
| CVE-2025-10360 | Media (6.9) | 0.19% | — | 24 sept 2025 | In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the… |
| CVE-2025-5459 | Alta (8.6) | 1.1% | — | 26 jun 2025 | A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3… |
| CVE-2023-5309 | Crítica (9.8) | 0.50% | — | 7 nov 2023 | Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations. |
| CVE-2023-5255 | Alta (7.5) | 0.41% | — | 3 oct 2023 | For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked. |
| CVE-2023-2530 | Crítica (9.8) | 1.1% | — | 7 jun 2023 | A privilege escalation allowing remote code execution was discovered in the orchestration service. |
| CVE-2023-1894 | Media (5.3) | 0.44% | — | 4 may 2023 | A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. |
| CVE-2021-27026 | Media (4.4) | 0.25% | — | 18 nov 2021 | A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged |
| CVE-2021-27025 | Media (6.5) | 1.1% | — | 18 nov 2021 | A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. |
| CVE-2021-27023 | Crítica (9.8) | 1.4% | — | 18 nov 2021 | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007 |
| CVE-2021-27022 | Media (4.9) | 0.92% | — | 7 sept 2021 | A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory… |
| CVE-2021-27020 | Alta (8.8) | 1.1% | — | 30 ago 2021 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. |
| CVE-2021-27019 | Media (4.3) | 0.74% | — | 30 ago 2021 | PuppetDB logging included potentially sensitive system information. |
| CVE-2021-27021 | Alta (8.8) | 1.3% | — | 20 jul 2021 | A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query. |
| CVE-2020-7943 | Alta (7.5) | 7.9% | — | 11 mar 2020 | Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for… |
| CVE-2015-5686 | Alta (8.8) | 0.45% | — | 27 feb 2020 | Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a… |
| CVE-2019-10694 | Crítica (9.8) | 1.1% | — | 12 dic 2019 | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default… |
| CVE-2013-4968 | Media (6.1) | 0.82% | — | 11 dic 2019 | Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors… |
| CVE-2015-1855 | Media (5.9) | 2.8% | — | 29 nov 2019 | verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers… |
| CVE-2018-11749 | Crítica (9.8) | 0.76% | — | 24 ago 2018 | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed… |
| CVE-2018-6513 | Alta (8.8) | 1.1% | — | 11 jun 2018 | Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and… |
| CVE-2018-6512 | Crítica (9.8) | 1.9% | — | 11 jun 2018 | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and… |
| CVE-2018-6511 | Media (5.4) | 0.65% | — | 8 may 2018 | A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Puppet Enterprise Console. Affected releases are… |
| CVE-2018-6510 | Media (5.4) | 0.52% | — | 8 may 2018 | A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts into the Puppet Enterprise Console when using the Orchestrator. Affected releases are Puppet Puppet… |
| CVE-2018-6508 | Alta (8) | 1.9% | — | 9 feb 2018 | Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the… |
| CVE-2017-10690 | Media (6.5) | 1.0% | — | 9 feb 2018 | In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet… |
| CVE-2017-10689 | Media (5.5) | 0.36% | — | 9 feb 2018 | In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability. |
| CVE-2017-2297 | Alta (7.5) | 0.64% | — | 1 feb 2018 | Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issue has been fixed in Puppet Enterprise 2016.4.5 and 2017.2.1. This only… |
| CVE-2017-2296 | Media (6.5) | 0.88% | — | 1 feb 2018 | In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.