CVE-2013-1654: Medium severity puppet vulnerability
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1654?
CVE-2013-1654 is considered a moderate severity vulnerability due to the potential for remote attackers to conduct SSLv2 downgrade attacks.
How do I fix CVE-2013-1654?
To fix CVE-2013-1654, upgrade Puppet to version 2.7.21 or 3.1.1 or later.
Which versions are affected by CVE-2013-1654?
CVE-2013-1654 affects Puppet versions 2.7.x before 2.7.21, 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2.
Can CVE-2013-1654 lead to data theft?
Yes, CVE-2013-1654 can potentially lead to data theft as it allows attackers to compromise SSL connections.
Is CVE-2013-1654 specific to certain platforms or operating systems?
CVE-2013-1654 primarily affects Puppet and Puppet Enterprise software, and it may be present on systems running affected versions regardless of the underlying operating system.