CVE-2023-5214: Puppet Bolt

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

Affected products

  • Puppet Bolt: before 3.27.4 (fixed in 3.27.4)

Published 2023-10-06. Last modified 2026-06-17.