Back

MEDIUM

puppet: insufficient validation of agent names in CN of SSL certificate requests

Published Aug 6, 2012

Description

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 6, 2012
Updated Aug 6, 2024
Reserved Jul 6, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 10, 2012
GHSA-Q44R-F2HM-V76V