PT-2012-5050 · Puppet+1 · Puppet+2

Published

2012-08-06

·

Updated

2019-07-10

·

CVE-2012-3867

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Puppet versions prior to 2.6.17 Puppet versions 2.7.x prior to 2.7.18 Puppet Enterprise versions prior to 2.5.2
Description The issue arises from the improper restriction of characters in the Common Name field of a Certificate Signing Request (CSR) in the lib/puppet/ssl/certificate authority.rb file. This makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
Recommendations For Puppet versions prior to 2.6.17, update to version 2.6.17 or later. For Puppet versions 2.7.x prior to 2.7.18, update to version 2.7.18 or later. For Puppet Enterprise versions prior to 2.5.2, update to version 2.5.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3867
DSA-2511-1
GHSA-Q44R-F2HM-V76V
OPENSUSE-SU-2024:10581-1

Affected Products

Puppet
Puppet Enterprise
Suse