First published: Thu Dec 21 2017(Updated: )
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Puppet Enterprise | >=3.7.0<=3.7.2 | |
Puppet Puppet Enterprise | =3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-4100 is medium.
The vulnerability in Puppet Enterprise 3.7.x and 3.8.0 is a Certificate Authority Reverse Proxy Vulnerability.
Remote authenticated users can exploit CVE-2015-4100 by managing certificates for arbitrary nodes using a trusted client certificate.
Versions 3.7.x (up to 3.7.2) and 3.8.0 of Puppet Enterprise are affected by CVE-2015-4100.
More information about CVE-2015-4100 can be found at https://puppet.com/security/cve/CVE-2015-4100.