RubySec

Providing security resources for the Ruby community

CVE-2023-5214 (bolt): Puppet Bolt privilege escalation vulnerability

Puppet Bolt privilege escalation vulnerability

Published: October 06, 2023

SECURITY IDENTIFIERS

GEM

bolt

SEVERITY

CVSS v3.x: 9.8 (Critical)

PATCHED VERSIONS

>= 3.27.4

DESCRIPTION

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

RELATED