The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPuppet Enterprise
APPPuppet2018.1.0 – 2018.1.9 (excl.)2019.0 – 2019.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-2530CRITICAL9.8PL ✓same product
Puppet Enterprise — privilege escalation i RCE w usłudze orkiestracji
CVE-2021-27023CRITICAL9.8PL ✓same product
Wyciek poświadczeń HTTP przy przekierowaniach w Puppet Agent i Puppet Server
CVE-2018-11749CRITICAL9.8PL ✓same product
Puppet Enterprise: przesyłanie poświadczeń LDAP w postaci jawnego tekstu przy startTLS
CVE-2018-6512CRITICAL9.8PL ✓same product
Puppet Enterprise — niebezpieczne wykonanie kodu przy aktualizacji pe-razor-server
CVE-2016-2788CRITICAL9.8PL ✓same product
RCE w Puppet MCollective przez komendę mco ping