Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-27023

Опубликовано: 18 нояб. 2021
Источник: debian
EPSS Низкий

Описание

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

Пакеты

ПакетСтатусВерсия исправленияРелизТип
puppetremovedpackage
puppetignoredbullseyepackage
puppetignoredbusterpackage
puppetignoredstretchpackage
puppet-agentnot-affectedpackage
puppetservernot-affectedpackage

Примечания

  • https://puppet.com/security/cve/cve-2021-27023

  • https://github.com/puppetlabs/puppet/commit/e90023a8b54a58073d71dae655d7636e2c9bcc61 (6.25.1)

  • Marginal/unclear security implications, the redirects are fully under control of

  • the puppet masters and the advisory states this CVE would be similar to CVE-2018-1000007,

  • but CVE is for curl, which obviously has different scope being a library. Plus, all

  • reasonably secure installations use client auth on the agents

  • Previous client code in lib/puppet/network/http/connection.rb also vulnerable

EPSS

Процентиль: 49%
0.00261
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

CVSS3: 9.8
redhat
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

CVSS3: 9.8
nvd
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

suse-cvrf
больше 2 лет назад

Security update for rubygem-puppet

suse-cvrf
почти 3 года назад

Security update for puppet

EPSS

Процентиль: 49%
0.00261
Низкий