PT-2011-1172 · Puppet · Puppet Enterprise (Pe) Users+1
Michael Stahnke
·
Published
2011-10-27
·
Updated
2019-07-11
·
CVE-2011-3872
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Puppet versions 2.6.x through 2.6.11
Puppet versions 2.7.x through 2.7.5
Puppet Enterprise (PE) Users versions 1.0 through 1.2.3
Description
The issue allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master. This can lead to a violation of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally.
Recommendations
For Puppet versions 2.6.x through 2.6.11, update to version 2.6.12 or later.
For Puppet versions 2.7.x through 2.7.5, update to version 2.7.6 or later.
For Puppet Enterprise (PE) Users versions 1.0 through 1.2.3, update to version 1.2.4 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Puppet
Puppet Enterprise (Pe) Users