CVE-2014-9355: Puppet Enterprise
Medium severity, CVSS 4.0. EPSS: 0.6% chance of exploitation in the next 30 days.
Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request information by leveraging access to an unspecified API endpoint.
Affected products
- Puppet Puppet Enterprise: up to and including 3.7.0
Published 2014-12-19. Last modified 2026-06-17.