{"id":"GHSA-289m-2964-f8q5","summary":"Puppet Bolt privilege escalation vulnerability","details":"In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.\n","aliases":["CVE-2023-5214"],"modified":"2024-02-16T08:13:05.594543Z","published":"2023-10-06T18:30:32Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-10-10T22:28:50Z","nvd_published_at":"2023-10-06T18:15:12Z","cwe_ids":["CWE-269"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5214"},{"type":"PACKAGE","url":"https://github.com/puppetlabs/bolt"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bolt/CVE-2023-5214.yml"},{"type":"WEB","url":"https://www.puppet.com/security/cve/cve-2023-5214-privilege-escalation-puppet-bolt"},{"type":"WEB","url":"https://www.puppet.com/security/cve/cve-2023-5255-denial-service-revocation-auto-renewed-certificates"}],"affected":[{"package":{"name":"bolt","ecosystem":"RubyGems","purl":"pkg:gem/bolt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.27.4"}]}],"versions":["0.0.1","0.10.0","0.11.0","0.12.0","0.13.0","0.14.0","0.15.0","0.16.0","0.16.1","0.16.2","0.16.3","0.16.4","0.17.0","0.17.1","0.17.2","0.18.0","0.18.1","0.18.2","0.19.0","0.19.1","0.20.0","0.20.2","0.20.3","0.20.5","0.20.6","0.20.7","0.21.0","0.21.1","0.21.2","0.21.3","0.21.4","0.21.5","0.21.6","0.21.7","0.21.8","0.22.0","0.23.0","0.24.0","0.25.0","0.5.0","0.5.1","0.6.0","0.6.1","0.7.0","0.8.0","0.9.0","1.0.0","1.1.0","1.10.0","1.11.0","1.12.0","1.13.0","1.13.1","1.14.0","1.15.0","1.16.0","1.17.0","1.18.0","1.19.0","1.2.0","1.20.0","1.21.0","1.22.0","1.23.0","1.24.0","1.25.0","1.26.0","1.27.0","1.27.1","1.28.0","1.29.0","1.29.1","1.3.0","1.30.0","1.30.1","1.31.0","1.31.1","1.32.0","1.33.0","1.34.0","1.35.0","1.36.0","1.37.0","1.38.0","1.39.0","1.4.0","1.40.0","1.41.0","1.42.0","1.43.0","1.44.0","1.45.0","1.47.0","1.48.0","1.49.0","1.5.0","1.6.0","1.7.0","1.8.0","1.8.1","1.9.0","2.0.0","2.0.1","2.1.0","2.10.0","2.11.0","2.11.1","2.12.0","2.13.0","2.14.0","2.15.0","2.16.0","2.17.0","2.18.0","2.19.0","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.24.0","2.24.1","2.25.0","2.26.0","2.27.0","2.28.0","2.29.0","2.3.0","2.3.1","2.30.0","2.31.0","2.32.0","2.33.1","2.33.2","2.34.0","2.35.0","2.36.0","2.37.0","2.38.0","2.4.0","2.40.1","2.40.2","2.42.0","2.44.0","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","3.0.0","3.0.1","3.1.0","3.10.0","3.11.0","3.12.0","3.13.0","3.14.1","3.15.0","3.16.0","3.16.1","3.17.0","3.18.0","3.19.0","3.20.0","3.21.0","3.22.0","3.22.1","3.23.0","3.23.1","3.24.0","3.25.0","3.26.1","3.26.2","3.27.1","3.27.2","3.3.0","3.4.0","3.5.0","3.6.0","3.6.1","3.7.0","3.7.1","3.8.0","3.8.1","3.9.0","3.9.1","3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-289m-2964-f8q5/GHSA-289m-2964-f8q5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}