CVE-2025-5459 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It af…
High CVSS: 8.6

CVE-2025-5459

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.
Vendor
Puppet
Product
Puppet Enterprise
CWE
CWE-78
Yayın Tarihi
2025-06-26 07:15:27
Güncelleme
2025-10-14 17:00:33
Source Identifier
security@puppet.com
KEV Date Added
-

Kategoriler

Referanslar