CVE-2023-2530: Puppet Enterprise

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A privilege escalation allowing remote code execution was discovered in the orchestration service.

Affected products

  • Puppet Puppet Enterprise: from 2021.7.0, up to and including 2021.7.3; version 2023.0 only; version 2023.1.0 only

Published 2023-06-07. Last modified 2026-06-17.