MEDIUM
Puppet: SSL protocol downgrade
Published Mar 20, 2013
5.0
MEDIUMCVSS 2.0
EPSS 2.95%
Description
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
Affected products
No data.
Configuration 1
OR
- 2.7.2
- 2.7.3
- 2.7.4
- 2.7.5
- 2.7.6
- 2.7.7
- 2.7.8
- 2.7.9
- 2.7.10
- 2.7.11
- 2.7.12
- 2.7.13
- 2.7.14
- 2.7.16
- 2.7.17
- 2.7.18
- 2.7.0
- 2.7.1
- 2.7.19
- 2.7.20
- 2.7.20
Configuration 2
- 3.1.0
Configuration 3
OR
- 2.7.0
- 2.7.1
Configuration 4
OR
- 11.10
- 12.04
- 12.10
No data.
OpenStack Folsom for RHEL 6
puppet-0:2.6.18-1.el6ost
Fixed · RHSA-2013:0710
Red Hat Enterprise MRG 1
puppet
Affected
Red Hat Subscription Asset Manager
puppet
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack Folsom for RHEL 6 | puppet-0:2.6.18-1.el6ost | Fixed | RHSA-2013:0710 |
| Red Hat Enterprise MRG 1 | puppet | Affected | n/a |
| Red Hat Subscription Asset Manager | puppet | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-0710.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/52596 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://ubuntu.com/usn/usn-1759-1 vendor-advisoryx_refsource_UBUNTU
- http://www.debian.org/security/2013/dsa-2643 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/64758 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-1654 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=919770 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-1654
- https://puppetlabs.com/security/cve/cve-2013-1654/ x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2013-1654
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html | vendor-advisoryx_refsource_SUSE | |
| http://rhn.redhat.com/errata/RHSA-2013-0710.html | vendor-advisoryx_refsource_REDHAT | |
| http://secunia.com/advisories/52596 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://ubuntu.com/usn/usn-1759-1 | vendor-advisoryx_refsource_UBUNTU | |
| http://www.debian.org/security/2013/dsa-2643 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/64758 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2013-1654 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=919770 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-1654 | ||
| https://puppetlabs.com/security/cve/cve-2013-1654/ | x_refsource_CONFIRMVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2013-1654 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 20, 2013
Updated Aug 6, 2024
Reserved Feb 11, 2013
Link CVE-2013-1654
CISA Vulnrichment
Updated n/a