Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75m2-x9qh-j7qr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

EPSS

Процентиль: 50%
0.00274
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 8 лет назад

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

CVSS3: 6.8
nvd
около 8 лет назад

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

CVSS3: 6.8
debian
около 8 лет назад

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated use ...

EPSS

Процентиль: 50%
0.00274
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-295