Man-in-the-Middle (MitM) Affecting puppet package, versions <2.6.12 >=2.7.0, <2.7.6
Threat Intelligence
EPSS
0.42% (75th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-PUPPET-20307
- published 28 Feb 2017
- disclosed 11 Oct 2011
- credit Puppet Labs
Introduced: 11 Oct 2011
CVE-2011-3872 Open this link in a new tabHow to fix?
Upgrade puppet
to version 2.6.12, 2.7.6 or higher.
Overview
puppet
is an automated configuration management tool.
Affected versions of the package are vulnerable to Remote Code Execution. It is possible for a malicious attacker to spoof the puppet
master by inserting the master's DNS alt names into the Subject Alternative Name
field of the certificate.
CVSS Scores
version 3.1