PT-2012-5050 · Puppet+1 · Puppet+2
Published
2012-08-06
·
Updated
2019-07-10
·
CVE-2012-3867
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Puppet versions prior to 2.6.17
Puppet versions 2.7.x prior to 2.7.18
Puppet Enterprise versions prior to 2.5.2
Description
The issue arises from the improper restriction of characters in the Common Name field of a Certificate Signing Request (CSR) in the
lib/puppet/ssl/certificate authority.rb file. This makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.Recommendations
For Puppet versions prior to 2.6.17, update to version 2.6.17 or later.
For Puppet versions 2.7.x prior to 2.7.18, update to version 2.7.18 or later.
For Puppet Enterprise versions prior to 2.5.2, update to version 2.5.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Puppet
Puppet Enterprise
Suse