For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
References
Link | Resource |
---|---|
https://www.puppet.com/security/cve/cve-2023-5255-denial-service-revocation-auto-renewed-certificates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Oct 2023, 16:48
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | (MISC) https://www.puppet.com/security/cve/cve-2023-5255-denial-service-revocation-auto-renewed-certificates - Vendor Advisory | |
CPE | cpe:2.3:a:puppet:puppet_server:8.2.0:*:*:*:*:*:*:* cpe:2.3:a:puppet:puppet_server:8.2.1:*:*:*:*:*:*:* cpe:2.3:a:puppet:puppet:2023.3:*:*:*:enterprise:*:*:* |
|
First Time |
Puppet puppet
Puppet puppet Server Puppet |
|
CWE | CWE-404 |
03 Oct 2023, 23:55
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
03 Oct 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-03 18:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-5255
Mitre link : CVE-2023-5255
CVE.ORG link : CVE-2023-5255
JSON object : View
Products Affected
puppet
- puppet
- puppet_server
CWE
CWE-404
Improper Resource Shutdown or Release