CVE-2025-5459

EUVD-2025-19173
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35.62%
Affected Products (NVD)
VendorProductVersion
puppetpuppet_enterprise
2018.1.8 ≤
𝑥
< 2023.8.4
puppetpuppet_enterprise
2025.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
puppetserver
bookworm
7.9.5-2+deb12u1
fixed
sid
8.7.0-7
fixed
trixie
8.7.0-5
fixed