Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27025

Опубликовано: 09 нояб. 2021
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

A configuration flaw was found in Puppet Agent where the agent silently ignores Augeas settings. This flaw allows a network attacker to cause a denial of service before the first pluginsync. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)puppetOut of support scope
Red Hat OpenStack Platform 13 (Queens)puppetOut of support scope
Red Hat Update Infrastructure 3 for Cloud ProviderspuppetWill not fix
Red Hat OpenStack Platform 16.1puppetFixedRHSA-2022:886207.12.2022
Red Hat OpenStack Platform 16.2puppetFixedRHSA-2022:884607.12.2022
Red Hat Satellite 6.10 for RHEL 7puppet-agentFixedRHSA-2022:170804.05.2022
Red Hat Satellite 6.10 for RHEL 7puppetserverFixedRHSA-2022:170804.05.2022
Red Hat Satellite 6.10 for RHEL 7puppet-agentFixedRHSA-2022:170804.05.2022
Red Hat Satellite 6.10 for RHEL 7puppetserverFixedRHSA-2022:170804.05.2022
Satellite Tools 6.10 for RHEL 6.ELSpuppet-agentFixedRHSA-2022:486601.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=2023853puppet: silent configuration failure in agent

EPSS

Процентиль: 38%
0.00166
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

CVSS3: 6.5
nvd
почти 4 года назад

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

CVSS3: 6.5
debian
почти 4 года назад

A flaw was discovered in Puppet Agent where the agent may silently ign ...

CVSS3: 6.5
github
почти 4 года назад

Silent Configuration Failure in Puppet Agent

CVSS3: 6.5
fstec
почти 4 года назад

Уязвимость приложения для запуска Puppet Agent, связанная с ошибками управления ресурсами, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00166
Низкий

6.3 Medium

CVSS3