Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Michael Stahnke

Pesquisador dePuppet Labs
#41958de 56,337
6.9CVSS total
Vulnerabilidades · 1
PT-2011-1172
6.9
2011-10-27
Puppet · Puppet Enterprise (Pe) Users · CVE-2011-3872
**Name of the Vulnerable Software and Affected Versions** Puppet versions 2.6.x through 2.6.11 Puppet versions 2.7.x through 2.7.5 Puppet Enterprise (PE) Users versions 1.0 through 1.2.3 **Description** The issue allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master. This can lead to a violation of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited locally. **Recommendations** For Puppet versions 2.6.x through 2.6.11, update to version 2.6.12 or later. For Puppet versions 2.7.x through 2.7.5, update to version 2.7.6 or later. For Puppet Enterprise (PE) Users versions 1.0 through 1.2.3, update to version 1.2.4 or later.