← Vulnerability feed

Vulnerability record · CVE-2023-5309 · published 7 November 2023

CVE-2023-5309: Puppet enterprise vulnerability

Puppet · Puppet Enterprise

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

9.8 CVSS 3.1 Critical EPSS 0.50% · top 59.9% CWE-384 · CWE-384
9.8CVSS 3.1 base score
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5309 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2530Puppet enterprise vulnerabilityA privilege escalation allowing remote code execution was discovered in the orchestration service.EPSS 1.1%9.8CVE-2021-27023Puppet agent vulnerabilityA flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…EPSS 1.4%9.8CVE-2019-10694Puppet enterprise hard-coded credentials vulnerabilityThe express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…EPSS 1.1%9.8CVE-2018-11749Puppet enterprise cleartext transmission vulnerabilityWhen users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…EPSS 0.76%9.8CVE-2018-6512Puppet pe-razor-server code injection vulnerabilityThe previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …EPSS 1.9%9.8CVE-2016-2788Puppet marionette collective improper access control vulnerabilityMCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …EPSS 2.3%9.8CVE-2016-2786Puppet agent improper input validation vulnerabilityThe pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…EPSS 1.6%9.0CVE-2013-1640Puppet vulnerabilityThe (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pup…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2023-5309), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.