CVE-2014-7170: Puppet Server
Low severity, CVSS 1.9. EPSS: 0.2% chance of exploitation in the next 30 days.
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.
Affected products
- Puppet Puppet Server: version 0.2.0 only
Published 2014-12-17. Last modified 2026-06-17.