Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3250

Опубликовано: 10 июн. 2014
Источник: redhat
CVSS2: 5

Описание

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.

Отчет

Not vulnerable. This issue did not affect the versions of puppet as shipped with Red Hat Subscription Asset Manager 1.3 as they did not include puppet-server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)puppetWill not fix
Red Hat OpenStack Platform 3puppetWill not fix
Red Hat OpenStack Platform 4puppetWill not fix
Red Hat Satellite 6puppetAffected
Red Hat Subscription Asset Managerruby193-puppetNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1101347puppet: certificates could be honored even when revoked

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.

CVSS3: 6.5
nvd
около 8 лет назад

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.

CVSS3: 6.5
debian
около 8 лет назад

The default vhost configuration file in Puppet before 3.6.2 does not i ...

CVSS3: 6.5
github
больше 3 лет назад

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.

suse-cvrf
больше 11 лет назад

Security update for puppet

5 Medium

CVSS2