QID 378697

Date Published: 2023-08-03

QID 378697: Puppet Enterprise Remote Code Execution (RCE) Vulnerability

Puppet is IT automation software that helps system administrators manage infrastructure throughout its lifecycle, from provisioning and configuration to orchestration and reporting.

A flaw was divered in Puppet Enterprise where sensitive plan parameters may be logged

Affected Versions:
Puppet Enterprise 2021.7.0 through Puppet Enterprise 2021.7.3
Puppet Enterprise 2023.0 and Puppet Enterprise 2023.1
QID Detection Logic:
Checking for vulnerable version on Puppet Enterprise server

A privilege escalation allowing remote code execution was discovered in the orchestration service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Updates to fix these vulnerability are available and its advised to upgrade to the latest version of the software. The latest version can be downloaded from CVE-2023-2530.

    CVEs related to QID 378697

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-2530 URL Logo www.puppet.com/security/cve/cve-2023-2530-remote-code-execution-orchestrator