CVE-2023-5309: Puppet Enterprise

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

Affected products

  • Puppet Puppet Enterprise: before 2021.7.6 (fixed in 2021.7.6); from 2023.0, before 2023.5.0 (fixed in 2023.5.0)

Published 2023-11-07. Last modified 2026-06-17.