CVE-2018-6517: High severity puppet vulnerability
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's knownhosts file without confirmation. In version 0.3.0 this is updated so that the user's knownhosts file is not updated by chloride.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6517?
The severity of CVE-2018-6517 is high with a CVSS score of 7.5.
What is the impact of CVE-2018-6517?
CVE-2018-6517 allows unauthorized modification of the user's known_hosts file.
How does chloride version 0.3.0 address CVE-2018-6517?
In version 0.3.0, chloride was updated to prevent the user's known_hosts file from being updated without confirmation.
Which software versions are affected by CVE-2018-6517?
Versions up to, but not including, 0.3.0 of chloride and Puppet Chloride are affected by CVE-2018-6517.
Where can I find more information about CVE-2018-6517?
You can find more information about CVE-2018-6517 at the following references: [reference 1](https://nvd.nist.gov/vuln/detail/CVE-2018-6517), [reference 2](https://web.archive.org/web/20201001014342/https://puppet.com/security/cve/CVE-2018-6517), [reference 3](https://github.com/rubysec/ruby-advisory-db/blob/master/gems/chloride/CVE-2018-6517.yml).