First published: Sun Mar 17 2019(Updated: )
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride.
Credit: security@puppet.com security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Chloride | <0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-6517 is high with a CVSS score of 7.5.
CVE-2018-6517 allows unauthorized modification of the user's known_hosts file.
In version 0.3.0, chloride was updated to prevent the user's known_hosts file from being updated without confirmation.
Versions up to, but not including, 0.3.0 of chloride and Puppet Chloride are affected by CVE-2018-6517.
You can find more information about CVE-2018-6517 at the following references: [reference 1](https://nvd.nist.gov/vuln/detail/CVE-2018-6517), [reference 2](https://web.archive.org/web/20201001014342/https://puppet.com/security/cve/CVE-2018-6517), [reference 3](https://github.com/rubysec/ruby-advisory-db/blob/master/gems/chloride/CVE-2018-6517.yml).