CVE-2011-3872: Input Validation
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3872?
The severity of CVE-2011-3872 is considered to be moderate due to potential certificate spoofing vulnerabilities.
How do I fix CVE-2011-3872?
To fix CVE-2011-3872, upgrade Puppet to version 2.6.12 or 2.7.6 or later, or Puppet Enterprise to version 1.2.4 or later.
What versions of Puppet are affected by CVE-2011-3872?
CVE-2011-3872 affects Puppet versions 2.6.x before 2.6.12 and 2.7.x before 2.7.6.
Can CVE-2011-3872 affect Puppet Enterprise Users?
Yes, CVE-2011-3872 affects Puppet Enterprise Users versions 1.0, 1.1, and 1.2 prior to 1.2.4.
What type of attack does CVE-2011-3872 enable?
CVE-2011-3872 allows remote attackers to spoof a Puppet master's certificate via manipulating X.509 Subject Alternative Name fields.