The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Computer vulnerabilities of Puppet Labs Puppet

jackson-databind: code execution via Axis2-transport-jms Deserialization
An attacker can use a vulnerability via Axis2-transport-jms Deserialization of jackson-databind, in order to run code...
5048, cpuapr2019, cpujul2019, cpuoct2019, CVE-2018-19360, DLA-1703-1, DSA-4452-1, FEDORA-2019-df57551f6d, RHSA-2019:0782-01, VIGILANCE-VUL-28546
jackson-databind: code execution via Openjpa Deserialization
An attacker can use a vulnerability via Openjpa of jackson-databind, in order to run code...
5048, cpuapr2019, cpujul2019, cpuoct2019, CVE-2018-19361, DLA-1703-1, DSA-4452-1, FEDORA-2019-df57551f6d, RHSA-2019:0782-01, VIGILANCE-VUL-28545
jackson-databind: code execution via Jboss-common-core Deserialization
An attacker can use a vulnerability via Jboss-common-core Deserialization of jackson-databind, in order to run code...
5048, cpuapr2019, cpujan2020, cpujul2019, cpuoct2019, CVE-2018-19362, DLA-1703-1, DSA-4452-1, FEDORA-2019-df57551f6d, RHSA-2019:0782-01, VIGILANCE-VUL-28544
Oracle MySQL: vulnerabilities of January 2019
Several vulnerabilities were announced in Oracle products...
bulletinapr2019, CERTFR-2019-AVI-025, cpujan2019, CVE-2019-2420, CVE-2019-2434, CVE-2019-2435, CVE-2019-2436, CVE-2019-2455, CVE-2019-2481, CVE-2019-2482, CVE-2019-2486, CVE-2019-2494, CVE-2019-2495, CVE-2019-2502, CVE-2019-2503, CVE-2019-2507, CVE-2019-2510, CVE-2019-2513, CVE-2019-2528, CVE-2019-2529, CVE-2019-2530, CVE-2019-2531, CVE-2019-2532, CVE-2019-2533, CVE-2019-2534, CVE-2019-2535, CVE-2019-2536, CVE-2019-2537, CVE-2019-2539, DLA-1655-1, FEDORA-2019-21b76d179e, openSUSE-SU-2019:0138-1, openSUSE-SU-2019:0327-1, openSUSE-SU-2020:0409-1, openSUSE-SU-2020:0430-1, RHSA-2019:1258-01, RHSA-2019:2327-01, RHSA-2019:2484-01, RHSA-2019:2511-01, RHSA-2019:3708-01, SSA:2019-032-01, SUSE-SU-2019:0555-1, SUSE-SU-2019:0609-1, SUSE-SU-2019:2048-1, SUSE-SU-2019:2118-1, USN-3867-1, VIGILANCE-VUL-28291
PostgreSQL: SQL injection via pg_upgrade/pg_dump
An attacker can use a SQL injection via pg_upgrade/pg_dump of PostgreSQL, in order to read or alter data...
528379, CVE-2018-16850, DLA-1642-1, DSA-2018-208, openSUSE-SU-2018:3893-1, openSUSE-SU-2018:4031-1, RHSA-2018:3757-01, SUSE-SU-2018:3770-1, SUSE-SU-2018:3770-2, USN-3818-1, VIGILANCE-VUL-27738
Oracle Java: vulnerabilities of October 2018
Several vulnerabilities were announced in Oracle products...
528379, CERTFR-2018-AVI-495, cpuoct2018, CVE-2018-3136, CVE-2018-3139, CVE-2018-3149, CVE-2018-3150, CVE-2018-3157, CVE-2018-3169, CVE-2018-3180, CVE-2018-3183, CVE-2018-3209, CVE-2018-3211, CVE-2018-3214, DLA-1590-1, DSA-2018-208, DSA-2019-131, DSA-4326-1, FEDORA-2018-209371341e, FEDORA-2018-369ab0efc9, FEDORA-2018-5857f28069, FEDORA-2018-cca64e06ba, FEDORA-2018-ce61c1147d, ibm10729607, ibm10741443, ibm10742147, ibm10742149, ibm10743955, ibm10793419, ibm10796096, ibm10875314, ibm10881644, ibm10882604, ibm10883400, openSUSE-SU-2018:3235-1, openSUSE-SU-2019:0042-1, openSUSE-SU-2019:0043-1, RHSA-2018:2942-01, RHSA-2018:2943-01, RHSA-2018:3000-01, RHSA-2018:3001-01, RHSA-2018:3002-01, RHSA-2018:3003-01, RHSA-2018:3007-01, RHSA-2018:3008-01, RHSA-2018:3350-01, RHSA-2018:3409-01, RHSA-2018:3521-01, RHSA-2018:3533-01, RHSA-2018:3534-01, RHSA-2018:3671-01, RHSA-2018:3672-01, SB10255, SUSE-SU-2018:3868-1, SUSE-SU-2018:3920-1, SUSE-SU-2018:3921-1, SUSE-SU-2018:3933-1, SUSE-SU-2018:4064-1, SUSE-SU-2019:0049-1, SUSE-SU-2019:0057-1, SUSE-SU-2019:0057-2, SUSE-SU-2019:0058-1, USN-3804-1, USN-3824-1, USN-3830-1, VIGILANCE-VUL-27509, ZDI-18-1263
Puppet Enterprise: privilege escalation via RBAC Plaintext Password
An attacker can bypass restrictions via RBAC Plaintext Password of Puppet Enterprise, in order to escalate his privileges...
CVE-2018-11749, VIGILANCE-VUL-27073
Guava: denial of service via AtomicDoubleArray
An attacker can generate a fatal error via AtomicDoubleArray() of Guava, in order to trigger a denial of service...
6198380, cpujul2020, CVE-2018-10237, ibm10795696, ibm10871804, RHSA-2018:2423-01, RHSA-2018:2424-01, RHSA-2018:2425-01, RHSA-2018:2740-01, RHSA-2018:2741-01, RHSA-2018:2742-01, RHSA-2018:2743-01, swg27048591, VIGILANCE-VUL-27021
rubyzip: directory traversal via Zip-File
An attacker can traverse directories via Zip::File of rubyzip, in order to create a file outside the service root path...
CVE-2018-1000544, DLA-1467-1, DLA-2307-1, VIGILANCE-VUL-27010
Oracle Java: vulnerabilities of July 2018
Several vulnerabilities were announced in Oracle products...
ADV-2018-022, CERTFR-2018-AVI-348, cpujul2018, CVE-2018-2938, CVE-2018-2940, CVE-2018-2941, CVE-2018-2942, CVE-2018-2952, CVE-2018-2964, CVE-2018-2972, CVE-2018-2973, DLA-1590-1, DSA-4268-1, FEDORA-2018-0b6ccd1c68, FEDORA-2018-40decc4158, FEDORA-2018-4d58785bcd, FEDORA-2018-877fdbb3f0, FEDORA-2018-c650019e9c, FEDORA-2018-d4bfa98f6a, ibm10725491, ibm10738401, ibm10742729, ibm10743351, NTAP-20180726-0001, openSUSE-SU-2018:2206-1, openSUSE-SU-2018:2247-1, openSUSE-SU-2018:3057-1, openSUSE-SU-2018:3103-1, openSUSE-SU-2019:0042-1, RHSA-2018:2241-01, RHSA-2018:2242-01, RHSA-2018:2253-01, RHSA-2018:2254-01, RHSA-2018:2255-01, RHSA-2018:2256-01, RHSA-2018:2283-01, RHSA-2018:2286-01, RHSA-2018:2568-01, RHSA-2018:2569-01, RHSA-2018:2575-01, RHSA-2018:2576-01, RHSA-2018:3007-01, RHSA-2018:3008-01, SB10247, SUSE-SU-2018:2083-1, SUSE-SU-2018:2574-1, SUSE-SU-2018:2583-1, SUSE-SU-2018:2649-1, SUSE-SU-2018:2839-1, SUSE-SU-2018:3045-1, SUSE-SU-2018:3064-1, SUSE-SU-2018:3064-3, SUSE-SU-2018:3082-1, SUSE-SU-2019:0049-1, USN-3734-1, USN-3735-1, USN-3747-1, USN-3747-2, VIGILANCE-VUL-26767
Our database contains other pages. You can request a free trial to read them.

Display information about Puppet Labs Puppet: