CVE-2023-2530: Puppet Enterprise
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A privilege escalation allowing remote code execution was discovered in the orchestration service.
Affected products
- Puppet Puppet Enterprise: from 2021.7.0, up to and including 2021.7.3; version 2023.0 only; version 2023.1.0 only
Published 2023-06-07. Last modified 2026-06-17.