Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 490
Alerts This Week
Warning Icon 1 490

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 33 articles for you...
203

Mageia 9 MGASA-2024-0136 critical: Puppet Security Fixes

The updated packages fix missing requires for puppet and fix commands in systemd units. References: - https://bugs.mageia.org/show_bug.cgi?id=29710 . MGASA-2024-0136 - Updated puppet packages fix security vulnerabilities Publication date: 18 Apr 2024 URL: https://advisories.mageia.org/MGASA-2024-0136.html Type: security Affected Mageia releases: 9 The updated packages fix missing requires for puppet and fix commands in systemd units. References: - https://bugs.mageia.org/show_bug.cgi?id=29710 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7 SRPMS: - 9/core/puppet-7.12.1-3.1.mga9 . Revamped puppet modules address vulnerabilities and corrections in systemd commands for Mageia 9. Release date: 18 Apr 2024.. Mageia Security, Puppet Updates, Critical Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 18, 2024 Critical Mageia
98

Red Hat OpenStack 16.1.9 RHSA-2022:8862-01 Moderate Puppet Issue

An update for puppet is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.1.9 (puppet) security update Advisory ID: RHSA-2022:8862-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:8862 Issue date: 2022-12-07 CVE Names: CVE-2021-27025 ==================================================================== 1. Summary: An update for puppet is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 16.1 - noarch 3. Description: A network tool for managing many disparate systems Security Fix(es): * silent configuration failure in agent (CVE-2021-27025) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2023853 - CVE-2021-27025 puppet: silent configuration failure in agent 6. Package List: Red Hat OpenStack Platform16.1: Source: puppet-5.5.10-14.el8ost.src.rpm noarch: puppet-5.5.10-14.el8ost.noarch.rpm puppet-headless-5.5.10-14.el8ost.noarch.rpm puppet-server-5.5.10-14.el8ost.noarch.rpm Red Hat OpenStack Platform 16.1: Source: puppet-5.5.10-14.el8ost.src.rpm noarch: puppet-5.5.10-14.el8ost.noarch.rpm puppet-headless-5.5.10-14.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-27025 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY5FpW9zjgjWX9erEAQhZgw/+LWeBglQQMIA8d7qyG9qsGkadGedCSD29 e0vpGbNqQ6P5fzrrVJWJJi8OXTx1BXaxv1iC5ebW9yAKF8xMcqoPT3bOG/P/iCrQ Hf+L6LHfIkaEZNiwi3q9ruqJrplIhx4FUkBSKWjrLdfCVCnnhKZ/8jYhpXcGoSuo TMaBdkfQmC6EPtGWJfzg+RIHmRfGxoA45oXwpzVOdv/nmQWOBt82vmFoPIshNbb7 LnewdD6O1/zrWcuYodVpFZjBq4eek5wEDp9f9UmrOe82SiZd/llENzFCjdAwJZn0 Z9BYWPGS9GaEw/yy5gYGZvA0LSN/CMi2K78nXL6ILDfJmkDIBxy2QEg4ffImrh0w oZX5EHNARwYCIboJ12aKEPm9aUIOUImuz/lIR8Sihfcpwh+8bE3YbVBjxxYTABow 8ff4w8rkGnX4iLDqLHZ3AjYAmUaS2dFN7fwwJIVn5YvgiJY41GOKuV+pAvAOIfsH /ZsC8bJvX5P5SgAW+sJOmmHTqKjTZLp/lEDGiOvyO86oDW5FUhkAkPumyMb3oqmj 3jdFIC/2nsipmhO9ipm+SowKpfxhzgQQQoiGfrpzhunx8dbt3lubYIkvCjRXAYGN fiOXemZM//Okz1Yz6BWYjYEW604bUnKl1eefytpADLyNmoPGIosQXLE4SZOqDjQi r4H4E0kaqxU=Y5qh -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Timely security patch release for Red Hat OpenStack Platform 16.1.9 resolving puppet setup issues.. Red Hat OpenStack, Puppet Fix, Update Advisory, Security Measures. . LinuxSecurity.com Team

Calendar%202 Dec 08, 2022 Red Hat
98

Red Hat OpenStack 16.2.4 RHSA-2022:8846-01 Moderate Puppet Security Issue

An update for puppet is now available for Red Hat OpenStack Platform 16.2.4 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.2.4 (puppet) security update Advisory ID: RHSA-2022:8846-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:8846 Issue date: 2022-12-07 CVE Names: CVE-2021-27025 ==================================================================== 1. Summary: An update for puppet is now available for Red Hat OpenStack Platform 16.2.4 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 16.2 - noarch 3. Description: Puppet lets you centrally manage every important aspect of your system using a cross-platform specification language that manages all the separate elements normally aggregated in different files, like users, cron jobs, and hosts, along with obviously discrete elements like packages, services, and files. Provides the central puppet server daemon which provides manifests to clients. The server can also function as a certificate authority and file server. This puppet headless subpackage may be used when there is no need to have puppet agent running as a service, for example, in a container image. Security fix(es): puppet: silent configuration failure in agent: (CVE-2021-27025) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the Referencessection. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2023853 - CVE-2021-27025 puppet: silent configuration failure in agent 6. Package List: Red Hat OpenStack Platform 16.2: Source: puppet-5.5.10-14.el8ost.src.rpm noarch: puppet-5.5.10-14.el8ost.noarch.rpm puppet-headless-5.5.10-14.el8ost.noarch.rpm puppet-server-5.5.10-14.el8ost.noarch.rpm Red Hat OpenStack Platform 16.2: Source: puppet-5.5.10-14.el8ost.src.rpm noarch: puppet-5.5.10-14.el8ost.noarch.rpm puppet-headless-5.5.10-14.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-27025 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY5FpS9zjgjWX9erEAQgn4Q/+J+wJJneM+6Sru2J9+5e5cUumm5yIi+5R HosD5+OWjNu2SC78L/crwuHbSPCCOtkGNBZ0ce9qs5ICrcgVK+WOTYzKpgVvufwi WYLeCrAyRi+KYPCo+yeGvwMB4zKC/GMyxkY2e8nQnqEGhWvrVilZ4BhROdVc5/Ko 0j5+ZvaQu6xYJJ7c5s/Ih2QbDAFvPISlwIHPHz5G4v4VjBu/UbuhUm2K9XW8SnBk +IRT9f9QsSLGBwKRdGeLxSqKaPoJapjzw0jAx5djd/eROyEdMx3tfjNR4kvZsANc FKqSLoFXQ3pkzjmFjiRa/b1ZWb0YnytpwBdxevD0Uh1uvPSxLz9Qhx6UJQPQjOsm 9twevRxEIR8womf59F3VEIWT0MzbPIL0+cWL/RUjuPJCbafgaN5VmTWzSJhu4DO5 UG4ERlIF65VOj6zp2NK9qaHt5eAnewDOBu7dpnjUD7pZLaXwlKzlzeoElccmq6f6 nbQ5LZ5fwYK1pXYXDnW0WnVg1Necam6FxdKSAUIm3f6ODew4yliP7VwcOW3a/Bhp 5dzd1B+eHm7Fkxo/YfKLV3sWNbGKGt5cf/WSc7ojrsqbd55zzioqoBvX5868T5wK dwHxhumcBzQ3/QP4Fw1hwkD68HzMaRTifmfXDdIPtOhInAcVEJIWjf5YbW1iW9Ml gbFIhJs6YDo=8NYh -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An update for Puppet tackles a significantsecurity concern in Red Hat OpenStack Platform 16.2.4, improving overall system protection.. Red Hat OpenStack,Puppet Update,Security Fixes,OpenStack Platform 16.2,Moderate Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 08, 2022 Important Red Hat
100

SUSE: 2022:3355-1 Important: Fix Unsafe HTTP Redirect in Puppet

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for puppet ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3355-1 Rating: important References: #1192797 Cross-References: CVE-2021-27023 CVSS scores: CVE-2021-27023 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-27023 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Advanced Systems Management 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for puppet fixes the following issues: - CVE-2021-27023: Fixed unsafe HTTP redirect (bsc#1192797). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Advanced Systems Management 12: zypper in -t patch SUSE-SLE-Module-Adv-Systems-Management-12-2022-3355=1 Package List: - SUSE Linux Enterprise Module for Advanced Systems Management 12 (ppc64le s390x x86_64): puppet-3.8.5-15.18.1 puppet-server-3.8.5-15.18.1 References: https://www.suse.com/security/cve/CVE-2021-27023.html https://bugzilla.suse.com/1192797 . SUSE Security Patch for puppet addresses critical vulnerabilities, including potential HTTP redirection flaws, thereby enhancing system management security.. SUSE Puppet Update, Security Fixes, System Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 23, 2022 Important SuSE
198

Arch Linux: 202112-4 High: Ansible Authorization Vulnerability

The package puppet before version 6.23.0-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-202107-8 ======================================== Severity: Medium Date : 2021-07-01 CVE-ID : CVE-2021-27021 Package : puppet Type : privilege escalation Remote : Yes Link : https://security.archlinux.org/AVG-2105 Summary ====== The package puppet before version 6.23.0-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 6.23.0-1. # pacman -Syu "puppet> =6.23.0-1" The problem has been fixed upstream in version 6.23.0. Workaround ========= None. Description ========== A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query. This has been resolved in Puppet DB 6.17.0, 7.4.1, Platform 6.23, 7.7.0 and Puppet Enterprise 2021.2, 2019.8.7. Impact ===== A privilege escalation security issue allowed users to delete tables. References ========= https://www.puppet.com/docs/puppetdb/7/overview.html https://github.com/puppetlabs/puppetdb/commit/c146e624d230f7410fb648d58ae28c0e3cd457a2 https://github.com/puppetlabs/puppetdb/commit/f8dc81678cf347739838e42cc1c426d96406c266 https://github.com/puppetlabs/puppetdb/commit/72bd137511487643a3a6236ad9e72a5dd4a6fadb https://security.archlinux.org/CVE-2021-27021 . The Puppet software on Arch Linux prior to version 6.23.0-1 contains a moderately severe vulnerability that may allow privilege escalation. It's crucial to update immediately!. Arch Linux, Puppet Upgrade, Privilege Escalation Threat. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jul 03, 2021 Medium ArchLinux
100

SUSE: 2020:1057-1 Moderate: Puppet Information Disclosure Risk

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for puppet ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1057-1 Rating: moderate References: #1167645 Cross-References: CVE-2020-7942 Affected Products: SUSE Linux Enterprise Module for Advanced Systems Management 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for puppet fixes the following issues: - CVE-2020-7942: Added a warning for a vulnerable configuration option, which could allow for information disclosure in certain setups. Disabling it my break some setups. (bsc#1167645) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Advanced Systems Management 12: zypper in -t patch SUSE-SLE-Module-Adv-Systems-Management-12-2020-1057=1 Package List: - SUSE Linux Enterprise Module for Advanced Systems Management 12 (ppc64le s390x x86_64): puppet-3.8.5-15.12.1 puppet-server-3.8.5-15.12.1 References: https://www.suse.com/security/cve/CVE-2020-7942.html https://bugzilla.suse.com/1167645 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Oracle Security Advisory: A patch has been issued for Puppet addressing a critical information exposure issue.. SUSE Security Update, Puppet Management, Information Disclosure, Advanced Systems Management. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2020 SuSE
100

SUSE: 2017:2113-1 Important: Puppet Code Execution Threat

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for puppet ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:2113-1 Rating: important References: #1040151 Cross-References: CVE-2017-2295 Affected Products: SUSE Linux Enterprise Module for Advanced Systems Management 12 SUSE Linux Enterprise Desktop 12-SP3 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for puppet fixes the following issues: Security issue fixed: - CVE-2017-2295: Possible code execution vulnerability where an attacker could force YAML deserialization in an unsafe manner. In default, this update breaks a backwards compatibility with Puppet agents older than 3.2.2 as the SLE12 master doesn't support other fact formats than pson in default anymore. In order to allow users to continue using their SLE12 master/SLE11 agents setup and fix CVE-2017-2295 for the others, a new puppet master boolean option "dangerous_fact_formats" was added. When it's set to true it enables using dangerous fact formats (e.g. YAML). When it's set to false, only PSON fact format is accepted. (bsc#1040151) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Advanced Systems Management 12: zypper in -t patch SUSE-SLE-Module-Adv-Systems-Management-12-2017-1310=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2017-1310=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1310=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Module for Advanced Systems Management 12 (ppc64le s390x x86_64): puppet-3.8.5-15.3.3 puppet-server-3.8.5-15.3.3 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): puppet-3.8.5-15.3.3 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): puppet-3.8.5-15.3.3 References: https://www.suse.com/security/cve/CVE-2017-2295.html https://bugzilla.suse.com/1040151 . SUSE Security Update for puppet addresses potential code execution vulnerabilities and introduces features for enhanced safety compliance. Discover additional details here.. SUSE Linux Enterprise, Puppet Security Patch, YAML Deserialization, System Management Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 09, 2017 Important SuSE
197

Debian: DLA-1012-1 Critical Remote Code Execution in Puppet

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. . Package : puppet Version : 2.7.23-1~deb7u4 CVE ID : CVE-2017-2295 Debian Bug : 863212 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. For Debian 7 "Wheezy", these problems have been fixed in version 2.7.23-1~deb7u4, by enabling PSON serialization on clients and refusing non-PSON formats on the server. We recommend that you upgrade your puppet packages. Make sure you update all your clients before you update the server otherwise older clients won't be able to connect to the server. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Puppet security patch addresses CVE-2017-2295 to mitigate risky deserialization that could enable remote code execution.. puppet update, debian security, deserialization risk, remote execution fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 03, 2017 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200