CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
AI Score
Confidence
Low
EPSS
Percentile
74.2%
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master’s certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka “AltNames Vulnerability.”
Vendor | Product | Version | CPE |
---|---|---|---|
puppet | puppet | 2.6.0 | cpe:2.3:a:puppet:puppet:2.6.0:*:*:*:*:*:*:* |
puppet | puppet | 2.6.1 | cpe:2.3:a:puppet:puppet:2.6.1:*:*:*:*:*:*:* |
puppet | puppet | 2.6.2 | cpe:2.3:a:puppet:puppet:2.6.2:*:*:*:*:*:*:* |
puppet | puppet | 2.6.3 | cpe:2.3:a:puppet:puppet:2.6.3:*:*:*:*:*:*:* |
puppet | puppet | 2.6.4 | cpe:2.3:a:puppet:puppet:2.6.4:*:*:*:*:*:*:* |
puppet | puppet | 2.6.5 | cpe:2.3:a:puppet:puppet:2.6.5:*:*:*:*:*:*:* |
puppet | puppet | 2.6.6 | cpe:2.3:a:puppet:puppet:2.6.6:*:*:*:*:*:*:* |
puppet | puppet | 2.6.7 | cpe:2.3:a:puppet:puppet:2.6.7:*:*:*:*:*:*:* |
puppet | puppet | 2.6.8 | cpe:2.3:a:puppet:puppet:2.6.8:*:*:*:*:*:*:* |
puppet | puppet | 2.6.9 | cpe:2.3:a:puppet:puppet:2.6.9:*:*:*:*:*:*:* |
groups.google.com/group/puppet-announce/browse_thread/thread/e7edc3a71348f3e1
puppetlabs.com/blog/important-security-announcement-altnames-vulnerability/
secunia.com/advisories/46550
secunia.com/advisories/46578
secunia.com/advisories/46934
secunia.com/advisories/46964
www.securityfocus.com/bid/50356
www.ubuntu.com/usn/USN-1238-1
www.ubuntu.com/usn/USN-1238-2
exchange.xforce.ibmcloud.com/vulnerabilities/70970
puppet.com/security/cve/cve-2011-3872