Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Puppet和Puppet Enterprise 证书安全漏洞
Vulnerability Description
Puppet是美国Puppet实验室的一套基于客户端/服务器(C/S)架构的配置管理工具。该工具可用于管理配置文件、用户、cron任务、软件包、系统服务等。 Puppet 2.6.17之前版本和2.7.18之前的2.7.x版本、Puppet Enterprise 2.5.2之前版本中的lib/puppet/ssl/certificate_authority.rb中存在漏洞,该漏洞源于未正确限制Certificate Signing Request (CSR)的Common Name字段中的字符。用户协助的
CVSS Information
N/A
Vulnerability Type
N/A