A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
2023-05-04T23:15:08.763
2025-01-29T18:15:44.620
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | puppet | puppet_enterprise | 2021.7.1 | Yes |
Application | puppet | puppet_enterprise | 2023.0 | Yes |
Application | puppet | puppet_server | 7.9.2 | Yes |