Lucene search

K
cvelistMitreCVELIST:CVE-2011-3848
HistoryOct 27, 2011 - 8:00 p.m.

CVE-2011-3848

2011-10-2720:00:00
mitre
www.cve.org
6

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

78.1%

Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

78.1%