First published: Tue Oct 03 2023(Updated: )
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
Credit: security@puppet.com security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Puppet | =2023.3 | |
Puppet Puppet Server | =8.2.0 | |
Puppet Puppet Server | =8.2.1 | |
=2023.3 | ||
=8.2.0 | ||
=8.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5255 is a vulnerability that affects certificates using the auto-renew feature in Puppet Server.
CVE-2023-5255 prevents the revocation of certificates that use the auto-renew feature in Puppet Server.
CVE-2023-5255 has a severity rating of high (7.5).
Puppet Server versions 8.2.0 and 8.2.1 are affected by CVE-2023-5255.
To fix CVE-2023-5255, update Puppet Server to a version that is not affected by the vulnerability.