CVE-2015-4100
EUVD-2015-412521.12.2017, 15:29
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| puppet | puppet_enterprise | 3.7.0 ≤ 𝑥 ≤ 3.7.2 |
| puppet | puppet_enterprise | 3.8.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration