CVE-2021-27018: High severity puppet remediate vulnerability
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27018?
CVE-2021-27018 is a vulnerability in the mechanism that performs certificate validation, allowing certificates signed by an internal certificate authority to not be properly validated.
What is the severity of CVE-2021-27018?
CVE-2021-27018 has a severity rating of 7.5 (high).
Which software is affected by CVE-2021-27018?
The Puppet Remediate software version up to and excluding 2.0.1 is affected by CVE-2021-27018.
How does CVE-2021-27018 impact clients configured to utilize Tenable.sc?
CVE-2021-27018 affects clients that are configured to utilize Tenable.sc as the vulnerability data source.
Where can I find more information about CVE-2021-27018?
You can find more information about CVE-2021-27018 at the following reference link: [link](https://puppet.com/security/cve/CVE-2021-27018).