CVE-2015-4100
21.12.2017, 15:29
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."Enginsight
Vendor | Product | Version |
---|---|---|
puppet | puppet_enterprise | 3.7.0 ≤ 𝑥 ≤ 3.7.2 |
puppet | puppet_enterprise | 3.8.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration