Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.
2019-12-16T22:15:11.043
2024-11-21T03:43:57.693
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:A/AC:L/Au:N/C:N/I:P/A:P
6.5
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | puppet | puppet_server | < 6.4.0 | Yes |