Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6x2-cpwm-cr43

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

EPSS

Процентиль: 45%
0.00223
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 12 лет назад

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

debian
почти 12 лет назад

The master external node classification script in Puppet Enterprise be ...

EPSS

Процентиль: 45%
0.00223
Низкий

Дефекты

CWE-287