Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frr9-9gjp-4944

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

EPSS

Процентиль: 39%
0.00174
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
почти 9 лет назад

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

CVSS3: 5.3
debian
почти 9 лет назад

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x befor ...

EPSS

Процентиль: 39%
0.00174
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284