Puppetlabs

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 34
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    21
    Medium Level Threats
    9
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2016-2787

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

    Last Modified: Apr 20, 2025
    Published: Feb 13, 2017

    CVE-2015-7331

    The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.

    Last Modified: Apr 20, 2025
    Published: Jan 30, 2017

    CVE-2015-1426

    facter: potential sensitive information leakage in Facter's Amazon EC2 metadata facts handling

    Last Modified: Apr 12, 2025
    Published: Feb 10, 2015

    CVE-2014-3251

    mcollective: aes_security.rb file creation vulnerability

    Last Modified: Apr 12, 2025
    Published: Jul 15, 2014

    CVE-2014-3248

    puppet: Ruby modules could be loaded from the current working directory

    Last Modified: Apr 12, 2025
    Published: Jun 10, 2014
    Items Per Page
    Puppetlabs Vulnerabilities & Security CVEs | CVE-DB