Puppet 3.2.4-1

CPE Details

Puppet 3.2.4-1
3.2.4-1
2018-05-23
15h09 +00:00
2018-05-23
15h09 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:puppet:puppet:3.2.4-1:*:*:*:*:*:*:*

Informations

Vendor

puppet

Product

puppet

Version

3.2.4-1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-27021 2021-07-20 08h44 +00:00 A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
8.8
High
CVE-2017-10689 2018-02-09 20h00 +00:00 In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
5.5
Medium
CVE-2017-10690 2018-02-09 20h00 +00:00 In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
6.5
Medium
CVE-2014-3250 2017-12-11 16h00 +00:00 The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
6.5
Medium
CVE-2017-2295 2017-07-05 15h00 +00:00 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.
8.2
High