Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-2294

Опубликовано: 05 июл. 2017
Источник: ubuntu
Приоритет: low
CVSS2: 5
CVSS3: 7.5

Описание

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.

РелизСтатусПримечание
devel

not-affected

PuppetDB not enabled
esm-apps/xenial

not-affected

PuppetDB not enabled
esm-infra-legacy/trusty

not-affected

PuppetDB not enabled
precise/esm

DNE

trusty

not-affected

PuppetDB not enabled
trusty/esm

not-affected

PuppetDB not enabled
upstream

needs-triage

vivid/ubuntu-core

DNE

xenial

not-affected

PuppetDB not enabled
yakkety

not-affected

PuppetDB not enabled

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.

CVSS3: 7.5
debian
больше 8 лет назад

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to ...

CVSS3: 7.5
github
больше 3 лет назад

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.

5 Medium

CVSS2

7.5 High

CVSS3