Back

HIGH

puppet-agent: pxp-agent attempts to configure OpenSSL from uncontrolled location

Published Jun 11, 2018

Description

Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of puppet-agent as shipped with Red Hat Satellite 6 as this issue is specific to Windows platform only.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner puppet
Published Jun 11, 2018
Updated Sep 16, 2024
Reserved Feb 1, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 7, 2018