CVE-2014-3250: Medium severity puppet vulnerability
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Other sources
Upstream reports:
"" In Apache 2.4, SSLCARevocationCheck directive was added to modssl, which defaults it to none and must be explicitly configured. This setting enables checking of a certificate revocation list. The default Puppet master vhost config shipped with Puppet does not include this setting. If a Puppet master is set up to run with Apache 2.4, and this default vhost configuration file is used, the Puppet master will continue to honor a host's certificate even after it is revoked. ""
Acknowledgements:
Red Hat would like to thank Puppet Labs for reporting this issue.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3250?
CVE-2014-3250 is classified as a medium severity vulnerability affecting Puppet versions before 3.6.2.
How do I fix CVE-2014-3250?
To fix CVE-2014-3250, upgrade Puppet to version 3.6.2 or later and ensure the SSLCARevocationCheck directive is included in your vhost configuration.
Which versions of Puppet are affected by CVE-2014-3250?
CVE-2014-3250 affects all Puppet versions prior to 3.6.2.
Can CVE-2014-3250 allow sensitive information to be exposed?
Yes, CVE-2014-3250 can allow remote attackers to potentially obtain sensitive information via a revoked certificate.
Which Apache version is associated with CVE-2014-3250?
CVE-2014-3250 is associated with Apache HTTP Server version 2.4.