Puppet Bolt privilege escalation vulnerability
Published: October 06, 2023
SECURITY IDENTIFIERS
- CVE: CVE-2023-5214 (NVD)
- GHSA: GHSA-289m-2964-f8q5
- Vendor Advisory: https://www.puppet.com/security/cve/cve-2023-5214-privilege-escalation-puppet-bolt
GEM
SEVERITY
CVSS v3.x: 9.8 (Critical)
PATCHED VERSIONS
>= 3.27.4
DESCRIPTION
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
