<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Puppet (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/puppet.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/puppet-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Puppet (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-5459 – A user with specific node group editing permissions and a specially crafted clas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5459</guid>
    <pubDate>Thu, 26 Jun 2025 07:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5459</strong></p>
  <p>A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7923 – An authentication bypass vulnerability has been identified in Pulpcore when depl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7923</guid>
    <pubDate>Wed, 04 Sep 2024 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7923</strong></p>
  <p>An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7012 – An authentication bypass vulnerability has been identified in Foreman when deplo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7012</guid>
    <pubDate>Wed, 04 Sep 2024 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7012</strong></p>
  <p>An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27294 – dp-golang is a Puppet module for Go installations.  Prior to 1.2.7, dp-golang co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27294</guid>
    <pubDate>Thu, 29 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27294</strong></p>
  <p>dp-golang is a Puppet module for Go installations.  Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25350 – All versions of the package puppet-facter are vulnerable to Command Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25350</guid>
    <pubDate>Thu, 26 Jan 2023 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25350</strong></p>
  <p>All versions of the package puppet-facter are vulnerable to Command Injection via the getFact  function due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3276 – Command injection is possible in the puppetlabs-mysql module prior to version 13...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3276</guid>
    <pubDate>Fri, 07 Oct 2022 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3276</strong></p>
  <p>Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3275 – Command injection is possible in the puppetlabs-apt module prior to version 9.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3275</guid>
    <pubDate>Fri, 07 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3275</strong></p>
  <p>Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27024 – A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27024</guid>
    <pubDate>Thu, 18 Nov 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27024</strong></p>
  <p>A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-27023 – A flaw was discovered in Puppet Agent and Puppet Server that may result in a lea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27023</guid>
    <pubDate>Thu, 18 Nov 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-27023</strong></p>
  <p>A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27020 – Puppet Enterprise presented a security risk by not sanitizing user input when do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27020</guid>
    <pubDate>Mon, 30 Aug 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27020</strong></p>
  <p>Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27021 – A flaw was discovered in Puppet DB, this flaw results in an escalation of privil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27021</guid>
    <pubDate>Tue, 20 Jul 2021 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27021</strong></p>
  <p>A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1027</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7944 – In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7944</guid>
    <pubDate>Thu, 26 Mar 2020 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7944</strong></p>
  <p>In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7943 – Puppet Server and PuppetDB provide useful performance and debugging information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7943</guid>
    <pubDate>Wed, 11 Mar 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7943</strong></p>
  <p>Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5686 – Parts of the Puppet Enterprise Console 3.x were found to be susceptible to click...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5686</guid>
    <pubDate>Thu, 27 Feb 2020 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5686</strong></p>
  <p>Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10694 – The express install, which is the suggested way to install Puppet Enterprise, gi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10694</guid>
    <pubDate>Thu, 12 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10694</strong></p>
  <p>The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10458 – Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10458</guid>
    <pubDate>Wed, 16 Oct 2019 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10458</strong></p>
  <p>Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11747 – Previously, Puppet Discovery was shipped with a default generated TLS certificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11747</guid>
    <pubDate>Thu, 21 Mar 2019 16:00:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11747</strong></p>
  <p>Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be able to provide their own TLS certificate for ingress.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11748 – Previous releases of the Puppet device_manager module creates configuration file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11748</guid>
    <pubDate>Tue, 02 Oct 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11748</strong></p>
  <p>Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11749 – When users are configured to use startTLS with RBAC LDAP, at login time, the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11749</guid>
    <pubDate>Fri, 24 Aug 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11749</strong></p>
  <p>When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11746 – In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11746</guid>
    <pubDate>Tue, 03 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11746</strong></p>
  <p>In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6516 – On Windows only, with a specifically crafted configuration file an attacker coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6516</guid>
    <pubDate>Thu, 14 Jun 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6516</strong></p>
  <p>On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6515 – Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Pup...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6515</guid>
    <pubDate>Mon, 11 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6515</strong></p>
  <p>Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6514 – In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Pupp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6514</guid>
    <pubDate>Mon, 11 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6514</strong></p>
  <p>In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6513 – Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6513</guid>
    <pubDate>Mon, 11 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6513</strong></p>
  <p>Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack where an unprivileged user on Windows agents could write custom facts that can escalate privileges on the next puppet r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-6512 – The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6512</guid>
    <pubDate>Mon, 11 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-6512</strong></p>
  <p>The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9599 – puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9599</guid>
    <pubDate>Tue, 24 Apr 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9599</strong></p>
  <p>puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6508 – Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6508</guid>
    <pubDate>Fri, 09 Feb 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6508</strong></p>
  <p>Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2297 – Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2297</guid>
    <pubDate>Thu, 01 Feb 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2297</strong></p>
  <p>Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issue has been fixed in Puppet Enterprise 2016.4.5 and 2017.2.1. This only affects users with labeled tokens, which is not the default for tokens.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5713 – Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Executi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5713</guid>
    <pubDate>Wed, 06 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5713</strong></p>
  <p>Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5714 – Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5714</guid>
    <pubDate>Wed, 18 Oct 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5714</strong></p>
  <p>Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5716 – The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5716</guid>
    <pubDate>Wed, 09 Aug 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5716</strong></p>
  <p>The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2295 – Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2295</guid>
    <pubDate>Wed, 05 Jul 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2295</strong></p>
  <p>Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2294 – Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MColl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2294</guid>
    <pubDate>Wed, 05 Jul 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2294</strong></p>
  <p>Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-2292 – Versions of MCollective prior to 2.10.4 deserialized YAML from agents without ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2292</guid>
    <pubDate>Fri, 30 Jun 2017 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-2292</strong></p>
  <p>Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective plugins, but there is a chance that third-party plugins could rely on this insecure behavior.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2290 – On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2290</guid>
    <pubDate>Fri, 03 Mar 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2290</strong></p>
  <p>On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-2788 – MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2788</guid>
    <pubDate>Mon, 13 Feb 2017 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-2788</strong></p>
  <p>MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-2786 – The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2786</guid>
    <pubDate>Fri, 10 Jun 2016 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-2786</strong></p>
  <p>The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-2785 – Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2785</guid>
    <pubDate>Fri, 10 Jun 2016 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-2785</strong></p>
  <p>Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7330 – Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a hos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7330</guid>
    <pubDate>Mon, 11 Apr 2016 21:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7330</strong></p>
  <p>Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-1842 – The puppet manifests in the Red Hat openstack-puppet-modules package before 2014...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1842</guid>
    <pubDate>Fri, 10 Apr 2015 15:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-1842</strong></p>
  <p>The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0210 – The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0210</guid>
    <pubDate>Thu, 08 May 2014 14:29:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0210</strong></p>
  <p>The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-1398 – The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not proper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1398</guid>
    <pubDate>Fri, 14 Mar 2014 16:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-1398</strong></p>
  <p>The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3567 – Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3567</guid>
    <pubDate>Mon, 19 Aug 2013 23:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3567</strong></p>
  <p>Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-1655 – Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or la...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1655</guid>
    <pubDate>Wed, 20 Mar 2013 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-1655</strong></p>
  <p>Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-1653 – Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1653</guid>
    <pubDate>Wed, 20 Mar 2013 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-1653</strong></p>
  <p>Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1640 – The (1) template and (2) inline_template functions in the master server in Puppe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1640</guid>
    <pubDate>Wed, 20 Mar 2013 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1640</strong></p>
  <p>The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-6557 – cgi-bin/webutil.pl in The Puppet Master WebUtil 2.7 allows remote attackers to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6557</guid>
    <pubDate>Mon, 30 Mar 2009 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-6557</strong></p>
  <p>cgi-bin/webutil.pl in The Puppet Master WebUtil 2.7 allows remote attackers to execute arbitrary commands via shell metacharacters in the details command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-6556 – cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6556</guid>
    <pubDate>Mon, 30 Mar 2009 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-6556</strong></p>
  <p>cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the whois command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-6555 – cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6555</guid>
    <pubDate>Mon, 30 Mar 2009 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-6555</strong></p>
  <p>cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6555">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
