Ruby/puppet/5.5.2
Puppet, an automated administrative engine for your Linux, Unix, and Windows systems, performs administrative tasks (such as adding users, installing packages, and updating server configurations) based on a centralized specification.
https://rubygems.org/gems/puppet
UNKNOWN
5 Security Vulnerabilities
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
- https://nvd.nist.gov/vuln/detail/CVE-2021-27023
- https://puppet.com/security/cve/CVE-2021-27023
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/
- https://github.com/advisories/GHSA-93j5-g845-9wqp
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2021-27023.yml
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Improper Certificate Validation in Puppet
Previously, Puppet operated on the model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the default
node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting strict_hostname_checking = true
in puppet.conf
on your Puppet master. Puppet 6.13.0 changes the default behavior for stricthostnamechecking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set stricthostnamechecking to true to ensure secure behavior.
Silent Configuration Failure in Puppet Agent
- https://nvd.nist.gov/vuln/detail/CVE-2021-27025
- https://puppet.com/security/cve/cve-2021-27025
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/
- https://github.com/advisories/GHSA-q4g7-jrxv-67r9
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2021-27025.yml
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Silent Configuration Failure in Puppet Agent
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
300 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
3.3.2 | UNKNOWN | 11 | 2013-11-12 - 21:28 | about 11 years |
3.3.1 | UNKNOWN | 11 | 2013-10-07 - 22:02 | about 11 years |
3.3.1.rc3 | UNKNOWN | 11 | 2013-10-02 - 22:49 | about 11 years |
3.3.1.rc2 | UNKNOWN | 11 | 2013-09-27 - 23:08 | about 11 years |
3.3.1.rc1 | UNKNOWN | 11 | 2013-09-24 - 00:11 | about 11 years |
3.3.0 | UNKNOWN | 11 | 2013-09-12 - 23:34 | about 11 years |
3.3.0.rc3 | UNKNOWN | 11 | 2013-09-09 - 23:15 | about 11 years |
3.3.0.rc2 | UNKNOWN | 11 | 2013-09-04 - 00:12 | about 11 years |
3.2.4 | UNKNOWN | 11 | 2013-08-15 - 16:15 | about 11 years |
3.2.3 | UNKNOWN | 13 | 2013-07-15 - 18:39 | over 11 years |
3.2.3.rc1 | UNKNOWN | 13 | 2013-07-03 - 00:14 | over 11 years |
3.2.2 | UNKNOWN | 13 | 2013-06-18 - 17:04 | over 11 years |
3.2.1 | UNKNOWN | 15 | 2013-05-22 - 18:58 | over 11 years |
3.2.1.rc1 | UNKNOWN | 15 | 2013-05-17 - 22:56 | over 11 years |
3.2.0.rc2 | UNKNOWN | 13 | 2013-05-07 - 17:40 | over 11 years |
3.2.0.rc1 | UNKNOWN | 13 | 2013-04-18 - 20:38 | over 11 years |
3.1.1 | UNKNOWN | 13 | 2013-03-12 - 16:58 | over 11 years |
3.1.0 | UNKNOWN | 15 | 2013-02-04 - 19:25 | almost 12 years |
3.1.0.rc2 | UNKNOWN | 14 | 2013-01-25 - 23:24 | almost 12 years |
3.1.0.rc1 | UNKNOWN | 14 | 2013-01-09 - 22:34 | almost 12 years |
3.0.2 | UNKNOWN | 14 | 2012-12-27 - 00:13 | almost 12 years |
3.0.2.rc3 | UNKNOWN | 14 | 2012-12-14 - 23:15 | almost 12 years |
3.0.2.rc2 | UNKNOWN | 14 | 2012-12-12 - 00:39 | almost 12 years |
3.0.2.rc1 | UNKNOWN | 14 | 2012-12-04 - 19:05 | almost 12 years |
3.0.1 | UNKNOWN | 14 | 2012-10-18 - 18:44 | about 12 years |
3.0.1.rc1 | UNKNOWN | 14 | 2012-10-12 - 06:12 | about 12 years |
3.0.0 | UNKNOWN | 14 | 2012-09-28 - 18:21 | about 12 years |
3.0.0.rc8 | UNKNOWN | 13 | 2012-09-25 - 21:32 | about 12 years |
3.0.0.rc7 | UNKNOWN | 13 | 2012-09-21 - 22:50 | about 12 years |
3.0.0.rc5 | UNKNOWN | 13 | 2012-08-29 - 23:49 | about 12 years |
3.0.0.rc4 | UNKNOWN | 13 | 2012-08-25 - 00:23 | about 12 years |
2.7.26 | UNKNOWN | 9 | 2014-06-10 - 18:15 | over 10 years |
2.7.25 | UNKNOWN | 10 | 2014-01-07 - 18:14 | almost 11 years |
2.7.24 | UNKNOWN | 10 | 2013-12-26 - 23:45 | almost 11 years |
2.7.23 | UNKNOWN | 10 | 2013-08-15 - 16:14 | about 11 years |
2.7.22 | UNKNOWN | 11 | 2013-06-18 - 17:04 | over 11 years |
2.7.21 | UNKNOWN | 12 | 2013-03-12 - 18:15 | over 11 years |
2.7.20 | UNKNOWN | 13 | 2012-11-20 - 02:22 | almost 12 years |
2.7.20.rc1 | UNKNOWN | 13 | 2012-11-10 - 17:08 | about 12 years |
2.7.19 | UNKNOWN | 13 | 2012-08-21 - 21:54 | about 12 years |
2.7.18 | UNKNOWN | 13 | 2012-07-11 - 01:04 | over 12 years |
2.7.17 | UNKNOWN | 21 | 2012-06-20 - 00:25 | over 12 years |
2.7.16 | UNKNOWN | 21 | 2012-06-14 - 01:36 | over 12 years |
2.7.14 | UNKNOWN | 21 | 2012-05-02 - 18:33 | over 12 years |
2.7.13 | UNKNOWN | 21 | 2012-04-11 - 01:09 | over 12 years |
2.7.12 | UNKNOWN | 29 | 2012-03-12 - 17:38 | over 12 years |
2.7.11 | UNKNOWN | 29 | 2012-02-23 - 05:34 | over 12 years |
2.7.9 | UNKNOWN | 31 | 2011-12-10 - 02:51 | almost 13 years |
2.7.8 | UNKNOWN | 31 | 2011-12-09 - 06:47 | almost 13 years |
2.7.6 | UNKNOWN | 31 | 2011-10-24 - 19:57 | about 13 years |
2.7.5 | UNKNOWN | 31 | 2011-09-30 - 21:58 | about 13 years |
2.7.4 | UNKNOWN | 37 | 2011-09-28 - 23:35 | about 13 years |
2.7.3 | UNKNOWN | 37 | 2011-08-15 - 17:51 | about 13 years |
2.7.1 | UNKNOWN | 37 | 2011-06-22 - 22:41 | over 13 years |
2.6.18 | UNKNOWN | 14 | 2013-03-12 - 16:57 | over 11 years |
2.6.17 | UNKNOWN | 14 | 2012-07-11 - 01:03 | over 12 years |
2.6.16 | UNKNOWN | 16 | 2012-04-11 - 19:38 | over 12 years |
2.6.15 | UNKNOWN | 16 | 2012-04-11 - 01:09 | over 12 years |
2.6.14 | UNKNOWN | 19 | 2012-02-23 - 05:34 | over 12 years |
2.6.13 | UNKNOWN | 20 | 2011-12-12 - 22:53 | almost 13 years |
2.6.12 | UNKNOWN | 20 | 2011-10-24 - 19:57 | about 13 years |
2.6.11 | UNKNOWN | 20 | 2011-09-30 - 21:57 | about 13 years |
2.6.10 | UNKNOWN | 23 | 2011-09-28 - 23:35 | about 13 years |
2.6.9 | UNKNOWN | 23 | 2011-06-21 - 22:05 | over 13 years |
2.6.8 | UNKNOWN | 23 | 2011-04-27 - 21:15 | over 13 years |
2.6.7 | UNKNOWN | 23 | 2011-03-24 - 22:35 | over 13 years |
2.6.6 | UNKNOWN | 23 | 2011-03-09 - 22:47 | over 13 years |
2.6.5 | UNKNOWN | 23 | 2011-03-01 - 01:03 | over 13 years |
2.6.4 | UNKNOWN | 23 | 2010-12-01 - 21:05 | almost 14 years |
2.6.3 | UNKNOWN | 25 | 2010-11-16 - 23:09 | almost 14 years |
2.6.2 | UNKNOWN | 25 | 2010-10-07 - 19:18 | about 14 years |
2.6.1 | UNKNOWN | 25 | 2010-09-14 - 01:54 | about 14 years |
2.6.0 | UNKNOWN | 25 | 2010-07-20 - 04:31 | over 14 years |
0.25.5 | UNKNOWN | 24 | 2010-05-18 - 00:42 | over 14 years |
0.25.4 | UNKNOWN | 24 | 2010-01-29 - 07:13 | almost 15 years |
0.25.3 | UNKNOWN | 24 | 2010-01-12 - 02:28 | almost 15 years |
0.25.2 | UNKNOWN | 24 | 2010-01-05 - 06:31 | almost 15 years |
0.25.1 | UNKNOWN | 26 | 2009-10-27 - 10:00 | about 15 years |
0.25.0 | UNKNOWN | 26 | 2009-09-24 - 22:19 | about 15 years |
0.24.9 | UNKNOWN | 24 | 2010-01-05 - 10:02 | almost 15 years |
0.24.8 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.7 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.6 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.5 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.4 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.3 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.2 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.1 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.24.0 | UNKNOWN | 25 | 2009-07-25 - 18:02 | over 15 years |
0.23.2 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.23.1 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.23.0 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.22.4 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.18.4 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.16.0 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.13.6 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.13.2 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.13.1 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.13.0 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |
0.9.2 | UNKNOWN | 24 | 2009-07-25 - 18:02 | over 15 years |