Lucene search

K
cvelistPuppetCVELIST:CVE-2023-1894
HistoryMay 04, 2023 - 10:13 p.m.

CVE-2023-1894

2023-05-0422:13:02
puppet
www.cve.org
regular expression dos
puppet server
certificate validation
security issue

5.7 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

CNA Affected

[
  {
    "vendor": "Puppet",
    "product": "Puppet Enterprise",
    "versions": [
      {
        "version": "2021.7.1",
        "status": "affected",
        "lessThan": "2021.7.3",
        "versionType": "semver"
      },
      {
        "version": "2023.0.0",
        "status": "affected",
        "lessThan": "2023.1.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "Puppet",
    "product": "Puppet Server",
    "versions": [
      {
        "version": "7.9.2",
        "status": "affected",
        "lessThan": "7.11.0",
        "versionType": "semver"
      },
      {
        "version": "7.9.2",
        "status": "affected",
        "lessThan": "8.0.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

5.7 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%