GHSA-gqvf-892r-vjm5

    Dashboard / Vulnerabilities / GHSA-gqvf-892r-vjm5

    GHSA-gqvf-892r-vjm5

    Published: 13 Apr 2021Last Modified: 22 Feb 2024
    Aliases:

    Summary: Improper Certificate Validation in Puppet

    Details: Previously, Puppet operated on the model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior.

    Affected packages

    Package

    Name: puppet

    Purl: pkg:gem/puppet

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 6.0.0
    Fixed -6.13.0

    Affected versions

    6.0.0
    6.0.1
    6.0.10
    6.0.2
    6.0.3
    6.0.4
    6.0.5
    6.0.7
    6.0.8
    6.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-gqvf-892r-vjm5 | CVE-DB