CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations. | 9.8 |
Critical |
||
A privilege escalation allowing remote code execution was discovered in the orchestration service. | 9.8 |
Critical |
||
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. | 5.3 |
Medium |