Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."
2017-12-21T15:29:00.237
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 6.8 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:P
6.8
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | puppet | puppet_enterprise | ≤ 3.7.2 | Yes |
Application | puppet | puppet_enterprise | 3.8.0 | Yes |