CVE-2023-5255: Denial of Service for Revocation of Auto Renewed Certificates
Published Oct 3, 2023
·Updated
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
Affected Software
4 affected components
Puppet Puppet=2023.3
Puppet Puppet Server=8.2.0
Puppet Puppet Server=8.2.1
Puppet Puppet Enterprise=2023.3
Event History
Oct 3, 2023
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5255?
CVE-2023-5255 is a vulnerability that affects certificates using the auto-renew feature in Puppet Server.
2
How does CVE-2023-5255 impact Puppet Server?
CVE-2023-5255 prevents the revocation of certificates that use the auto-renew feature in Puppet Server.
3
What is the severity of CVE-2023-5255?
CVE-2023-5255 has a severity rating of high (7.5).
4
Which versions of Puppet Server are affected by CVE-2023-5255?
Puppet Server versions 8.2.0 and 8.2.1 are affected by CVE-2023-5255.
5
How can I fix CVE-2023-5255?
To fix CVE-2023-5255, update Puppet Server to a version that is not affected by the vulnerability.