puppet-agent vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the puppet-agent package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Deserialization of Untrusted Data

*
  • M
Use After Free

*
  • M
Use After Free

*
  • L
External Control of File Name or Path

*
  • L
External Control of File Name or Path

*
  • L
Missing Encryption of Sensitive Data

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • L
Missing Encryption of Sensitive Data

*
  • H
Out-of-Bounds

*
  • H
Out-of-Bounds

*
  • L
Excessive Iteration

*
  • L
Excessive Iteration

*
  • M
Incorrect Regular Expression

*
  • M
Incorrect Regular Expression

*
  • M
Information Exposure Through Log Files

<0:5.5.12-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:5.5.12-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:5.5.12-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:5.5.12-1.el7sat
  • M
Information Exposure

<0:6.19.1-2.el7sat
  • M
Missing Authorization

<0:6.19.1-2.el7sat
  • M
Information Exposure Through Log Files

<0:6.19.1-2.el7sat
  • H
Information Exposure

<0:5.5.0-2.el7sat
  • H
SQL Injection

<0:5.5.0-2.el7sat
  • H
Information Exposure

<0:5.5.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:5.5.0-2.el7sat
  • H
Cross-site Scripting (XSS)

<0:5.5.0-2.el7sat
  • H
Cross-site Scripting (XSS)

<0:5.5.0-2.el7sat
  • H
XML External Entity (XXE) Injection

<0:5.5.0-2.el7sat
  • H
Information Exposure

<0:5.5.0-2.el7sat
  • H
Improper Input Validation

<0:6.14.0-2.el7sat
  • H
Use of a Broken or Risky Cryptographic Algorithm

<0:5.5.0-2.el7sat
  • H
Cross-site Scripting (XSS)

<0:6.14.0-2.el7sat
  • H
Improper Access Control

<0:5.5.0-2.el7sat
  • H
Missing Required Cryptographic Step

<0:5.5.0-2.el7sat
  • H
Missing Required Cryptographic Step

<0:5.5.0-2.el7sat
  • H
Information Exposure

<0:5.5.0-2.el7sat
  • H
Covert Timing Channel

<0:5.5.0-2.el7sat
  • H
Incorrect Calculation

<0:5.5.0-2.el7sat
  • H
Missing Required Cryptographic Step

<0:5.5.0-2.el7sat
  • H
Missing Required Cryptographic Step

<0:5.5.0-2.el7sat
  • H
Missing Required Cryptographic Step

<0:5.5.0-2.el7sat
  • M
Information Exposure

<0:6.19.1-2.el7sat
  • M
Directory Traversal

<0:5.5.12-1.el7sat
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

<0:5.5.0-2.el7sat
  • H
Improper Certificate Validation

<0:5.5.0-2.el7sat
  • M
CVE-2013-6668

<0:1.10.9-1.el7sat
  • M
Incorrect Permission Assignment for Critical Resource

<0:5.5.12-1.el7sat
  • M
Cleartext Storage of Sensitive Information

<0:5.5.12-1.el7sat
  • M
Improper Authentication

<0:5.5.12-1.el7sat
  • H
Information Exposure

<0:5.5.0-2.el7sat
  • H
Improper Authorization

<0:5.5.17-1.el7sat
  • H
Cleartext Transmission of Sensitive Information

<0:5.5.17-1.el7sat
  • H
Improper Certificate Validation

<0:5.5.17-1.el7sat
  • H
Insufficiently Protected Credentials

<0:6.14.0-2.el7sat
  • H
Improper Input Validation

<0:5.5.0-2.el7sat
  • H
Improper Input Validation

<0:5.5.0-2.el7sat
  • H
Cross-site Scripting (XSS)

<0:5.5.0-2.el7sat
  • H
Improper Authentication

<0:6.14.0-2.el7sat
  • M
Cross-site Scripting (XSS)

<0:5.5.12-1.el7sat
  • M
Information Exposure

<0:6.19.1-2.el7sat
  • H
Information Exposure

<0:6.14.0-2.el7sat
  • H
Incorrect Default Permissions

<0:6.14.0-2.el7sat
  • M
SQL Injection

<0:6.19.1-2.el7sat
  • H
Improperly Implemented Security Check for Standard

<0:6.14.0-2.el7sat
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<0:5.5.0-2.el7sat
  • H
Improper Initialization

<0:6.26.0-1.el7sat
  • H
Improper Initialization

<0:6.26.0-1.el7sat
  • H
Improper Initialization

<0:6.26.0-1.el7sat
  • H
Improper Initialization

<0:6.26.0-1.el7sat
  • H
Improper Initialization

<0:6.26.0-1.el7sat
  • H
Information Exposure

<0:6.26.0-1.el7sat
  • H
Information Exposure

<0:6.26.0-1.el7sat
  • H
Information Exposure

<0:6.26.0-1.el7sat
  • H
Information Exposure

<0:6.26.0-1.el7sat
  • H
Information Exposure

<0:6.26.0-1.el7sat
  • H
Information Exposure

<0:6.26.0-1.el7sat
  • L
Missing Authorization

*
  • H
Missing Authorization

<0:6.14.0-2.el7sat
  • M
Omission of Security-relevant Information

<0:1.10.9-1.el7sat
  • H
Information Exposure

<0:5.5.0-2.el7sat
  • M
Information Exposure

*
  • H
Improper Validation of Certificate with Host Mismatch

<0:6.14.0-2.el7sat
  • M
Improper Validation of Certificate with Host Mismatch

*
  • M
Execution with Unnecessary Privileges

<0:6.19.1-2.el7sat
  • H
HTTP Request Smuggling

<0:6.14.0-2.el7sat
  • M
Resource Exhaustion

<0:5.5.12-1.el7sat
  • M
Out-of-Bounds

<0:6.19.1-2.el7sat
  • M
Information Exposure

<0:6.19.1-2.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:6.19.1-2.el7sat
  • H
Cross-site Scripting (XSS)

<0:6.14.0-2.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:6.19.1-2.el7sat
  • H
Improper Input Validation

<0:6.14.0-2.el7sat
  • M
Cross-site Scripting (XSS)

<0:6.19.1-2.el7sat
  • M
Improper Input Validation

<0:6.19.1-2.el7sat
  • M
Improper Input Validation

<0:6.19.1-2.el7sat
  • H
Eval Injection

<0:6.14.0-2.el7sat
  • H
Directory Traversal

<0:6.14.0-2.el7sat
  • H
HTTP Response Splitting

<0:6.14.0-2.el7sat
  • H
Incomplete Blacklist

<0:5.5.0-2.el7sat
  • M
Arbitrary Command Injection

*
  • M
Arbitrary Command Injection

*
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:6.14.0-2.el7sat
  • M
Arbitrary Command Injection

*
  • M
Arbitrary Command Injection

*
  • M
Resource Exhaustion

<0:1.10.9-1.el7sat
  • M
HTTP Response Splitting

<0:5.5.12-1.el7sat
  • H
CVE-2018-3258

<0:6.14.0-2.el7sat
  • M
Covert Timing Channel

<0:6.19.1-2.el7sat
  • H
Covert Timing Channel

<0:6.14.0-2.el7sat
  • M
Arbitrary Argument Injection

<0:5.5.12-1.el7sat
  • H
Out-of-Bounds

<0:5.5.0-2.el7sat
  • M
Improper Neutralization of Special Elements

<0:5.5.12-1.el7sat
  • H
Deserialization of Untrusted Data

<0:5.5.17-1.el7sat
  • M
CVE-2016-6346

<0:5.5.12-1.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • M
Improper Neutralization of Special Elements

<0:5.5.12-1.el7sat
  • M
Information Exposure

<0:6.19.1-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • H
Deserialization of Untrusted Data

<0:6.14.0-2.el7sat
  • M
Use After Free

<0:6.19.1-2.el7sat
  • H
Deserialization of Untrusted Data

<0:5.5.17-1.el7sat