CVE-2015-4100: Medium severity puppet enterprise vulnerability
Published Dec 21, 2017
·Updated
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."
Affected Software
2 affected components
puppet Puppet Enterprise>=3.7.0<=3.7.2
puppet Puppet Enterprise=3.8.0
Event History
Dec 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4100?
The severity of CVE-2015-4100 is medium.
2
What is the vulnerability in Puppet Enterprise 3.7.x and 3.8.0?
The vulnerability in Puppet Enterprise 3.7.x and 3.8.0 is a Certificate Authority Reverse Proxy Vulnerability.
3
How can remote authenticated users exploit CVE-2015-4100?
Remote authenticated users can exploit CVE-2015-4100 by managing certificates for arbitrary nodes using a trusted client certificate.
4
Which versions of Puppet Enterprise are affected by CVE-2015-4100?
Versions 3.7.x (up to 3.7.2) and 3.8.0 of Puppet Enterprise are affected by CVE-2015-4100.
5
Where can I find more information about CVE-2015-4100?
More information about CVE-2015-4100 can be found at https://puppet.com/security/cve/CVE-2015-4100.