The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade puppet | Jul 30, 2024 | Dec 11, 2017 |
| Oracle Solaris | — | Upgrade system/management/puppet to version 3.6.2-0.175.2.5.0.2.0 on Solaris 11.2Upgrade system/management/puppet-19 to version 3.6.2-0.175.2.5.0.2.0 on Solaris 11.2 | May 29, 2017 | May 29, 2017 |
| Suse | — | Upgrade puppetUpgrade puppet-server | Dec 18, 2015 | Jul 8, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub