CVE-2018-11747: Critical severity puppet discovery vulnerability
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be able to provide their own TLS certificate for ingress.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11747?
CVE-2018-11747 is a vulnerability in Puppet Discovery where a default generated TLS certificate is shipped in the nginx container.
How severe is CVE-2018-11747?
CVE-2018-11747 has a severity rating of 9.8, which is classified as critical.
What software is affected by CVE-2018-11747?
Puppet Discovery versions up to but not including 1.4.0 are affected by CVE-2018-11747.
What is the recommended solution for CVE-2018-11747?
To fix CVE-2018-11747, users should upgrade Puppet Discovery to version 1.4.0 or apply a unique TLS certificate.
Where can I find more information about CVE-2018-11747?
More information about CVE-2018-11747 can be found at the following references: [Link 1](https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E), [Link 2](https://puppet.com/security/cve/CVE-2018-11747).