Puppet Enterprise
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*, +1 more
- >= 2018.1.8, <= 2023.8.3
- 2025.3
A command injection vulnerability has been identified in Puppet Enterprise. A user with specific permissions to edit node groups, along with a specially crafted class parameter, could execute commands as root on the primary host. This vulnerability affects Puppet Enterprise versions 2018.1.8 prior to 2023.8.3 and 2025.3, and has been resolved in versions 2023.8.4 and 2025.4.0.
Exploitation of this vulnerability allows for unauthorized command execution as the root user on the primary host.
Users can upgrade to Puppet Enterprise versions 2023.8.4 or 2025.4.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.