Known vulnerabilities in Puppet Server
Vendor:
Puppet Labs
Software:
Puppet Server
Software CPE:
cpe:2.3:a:puppet_labs:puppet_server:*:*:*:*:*:*:*:*
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
8.7.0
8.6.4
7.17.3
8.6.3
8.6.2
7.17.2
8.6.1
7.17.1
8.6.0
7.17.0
8.5.0
7.16.0
8.4.0
7.15.0
8.3.0
7.14.0
8.2.3
8.2.2
8.2.1
8.2.0
7.13.0
8.1.0
7.12.0
8.0.0
7.11.0
7.10.0
7.9.5
7.9.4
7.9.3
7.9.2
7.9.1
7.9.0
6.20.0
7.8.0
7.7.0
7.6.1
7.6.0
7.5.0
7.4.2
7.4.1
7.4.0
7.3.0
7.2.1
7.2.0
7.1.2
7.1.1
7.1.0
7.0.3
7.0.2
7.0.1
7.0.0
6.19.0
6.18.0
6.17.1
6.17.0
6.16.1
6.16.0
6.15.3
6.15.2
6.15.1
6.15.0
6.14.1
6.14.0
6.13.0
6.12.2
6.12.1
6.12.0
6.11.1
6.11.0
6.10.0
6.9.2
6.9.1
6.9.0
6.8.0
6.7.2
6.7.1
6.7.0
6.6.0
6.5.0
6.4.0
6.3.3
6.3.2
6.3.1
6.3.0
6.2.1
6.2.0
6.1.0
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
5.3.16
5.3.15
5.3.14
5.3.13
5.3.12
5.3.11
5.3.10
5.3.9
5.3.8
5.3.7
5.3.6
5.3.5
5.3.4
5.3.3
5.3.2
5.3.1
5.3.0
5.2.0
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
5.1.1
5.1.0
5.0.0
2.8.1
2.8.0
2.7.2
2.7.1
2.7.0
2.6.1
2.6.0
2.5.0
2.4.0
2.3.2
1.2.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83504 - Inefficient Regular Expression Complexity CVE-2023-1894 |
CWE-1333 | Medium | 7.11.0, 8.0.0 | 27.11.2023 |
SB2023050457 SB2023112747 |
||
| #VU62794 - Unprotected Transport of Credentials CVE-2021-27023 |
CWE-523 | Medium | 6.17.1, 7.4.2 | 04.05.2022 |
SB2022050414 SB2022050430 SB2022060135 and 5 more |