Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0675

Опубликовано: 28 фев. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

A flaw was found in the Puppet Firewall module. In certain situations, an unmanaged rule can exist on the target system that has the same comment as a rule specified in the manifest. When this condition is true, Puppet will ignore the unmanaged rule and continue to apply the rule in the manifest. This issue occurs because the firewall module uses the comment field in IPT as its namevar and therefore expects it to be a unique identifier. In the case of IPT, this is not true, given that you can have multiple rules with the same comment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)puppet-firewallAffected
Red Hat OpenStack Platform 16.1puppet-firewallFixedRHSA-2022:886907.12.2022
Red Hat OpenStack Platform 16.2puppet-firewallFixedRHSA-2022:511622.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2071567puppetlabs-firewall: unmanaged rules could leave system in an unsafe state via duplicate comment

EPSS

Процентиль: 66%
0.00519
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 4 года назад

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

CVSS3: 5.6
nvd
почти 4 года назад

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

CVSS3: 5.6
debian
почти 4 года назад

In certain situations it is possible for an unmanaged rule to exist on ...

CVSS3: 9.8
github
почти 4 года назад

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

EPSS

Процентиль: 66%
0.00519
Низкий

9.8 Critical

CVSS3