Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2021
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
CVSS Score
8.1
EPSS Score
0.003
Published
2021-11-18
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-11-18
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
CVSS Score
4.4
EPSS Score
0.001
Published
2021-11-18
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.
CVSS Score
8.8
EPSS Score
0.001
Published
2021-11-18
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.
CVSS Score
8.8
EPSS Score
0.012
Published
2021-11-18
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561381.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-11-18
In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561383.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-11-18
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561388.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-11-18
In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05585817.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-11-18
In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594988; Issue ID: ALPS05594988.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-11-18


Contact Us

Shodan ® - All rights reserved