PT-2025-5996 · Puppet · Puppet Agent

Published

2025-02-07

·

Updated

2025-02-08

·

CVE-2021-27017

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Puppet Agent versions prior to 7.4.0
Description The issue arises from the utilization of a module that presents a security risk by allowing the deserialization of untrusted or user-supplied data.
Recommendations For Puppet Agent versions prior to 7.4.0, update to version 7.4.0 to resolve the issue.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2021-27017

Affected Products

Puppet Agent