Puppet等都是美国Puppet实验室开发的产品。Puppet是一套基于客户端/服务器(C/S)架构的配置管理工具;Puppet Enterprise是一个企业版;Facter是一个用于获取客户端系统信息(如主机名、IP地址和操作系统版本等)的包。 多款Puppet产品中存在非信任搜索路径漏洞。当程序运行在Ruby 1.9.1及之前版本上时,本地攻击者可借助当前工作目录中的Trojan horse文件利用该漏洞获取权限。以下产品和版本受到影响:Puppet Enterprise 2.8.7之前2.8版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-8948 | WordPress iMember360插件跨站请求伪造漏洞 | |
| CVE-2014-2684 | Zend Framework ZendOpenId和Zend_OpenId_Consumer 安全漏洞 | |
| CVE-2014-2683 | 多款Zend产品拒绝服务漏洞 | |
| CVE-2014-2682 | 多款Zend产品安全漏洞 | |
| CVE-2014-2681 | 多款Zend产品安全漏洞 | |
| CVE-2014-3209 | ldns ldns-keygen 本地不安全文件权限漏洞 | |
| CVE-2014-2667 | Python'os._get_masked_mode()'函数竞争条件漏洞 | |
| CVE-2014-2268 | Vtiger CRM Install模块远程代码执行漏洞 | |
| CVE-2013-3737 | Best Practical Solutions Request Tracker MobileUI 信息泄露漏洞 | |
| CVE-2012-2301 | Drupal Ubercart模块任意PHP代码执行漏洞 | |
| CVE-2014-8949 | WordPress iMember360插件任意命令执行漏洞 | |
| CVE-2014-0228 | Apache Hive 安全绕过漏洞 | |
| CVE-2014-3756 | Mumble 拒绝服务漏洞 | |
| CVE-2014-3755 | Qt QSvg模块拒绝服务漏洞 | |
| CVE-2014-0233 | Red Hat OpenShift Enterprise 代码注入漏洞 | |
| CVE-2013-0347 | webfs ‘webfsd.log’不安全文件权限漏洞 | |
| CVE-2014-8952 | Check Point Security Gateway 拒绝服务漏洞 | |
| CVE-2014-8951 | Check Point Security Gateway 拒绝服务漏洞 | |
| CVE-2014-8950 | Check Point Security Gateway 拒绝服务漏洞 | |
| CVE-2014-3916 | Ruby‘string.c’内存损坏漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet