UBUNTU-CVE-2023-1894
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-1894
Summary:
Details: A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
References: https://ubuntu.com/security/CVE-2023-1894, https://www.puppet.com/security/cve/cve-2023-1894-puppet-server-redos, https://github.com/puppetlabs/puppetserver/pull/2700, https://github.com/puppetlabs/puppetserver/commit/545998b71baf70e35dc60c287f2cb2fc11ef9be2, https://github.com/puppetlabs/puppetserver/commit/9e0239c19bc852b98c1a63fb33998de7eae388dc, https://www.cve.org/CVERecord?id=CVE-2023-1894
Affected packages
Package
Name: puppet
Purl: pkg:deb/ubuntu/puppet?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
