Puppet Agent Deserialization of Untrusted Data Vulnerability
Vulnerability
Patched
A vulnerability in Puppet Agent prior to 7.4.0 allows for the deserialization of untrusted or user-supplied data, creating a potential security risk. This issue has been addressed in the Puppet Agent 7.4.0 release.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution, as deserializing untrusted data can commonly be manipulated to execute malicious code.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
