Puppet Firewall Module May Leave Unmanaged Rules
Published Mar 2, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.92%
Description
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.
Affected products
-
Affected
- ≥ prior to 3.4.0, < 3.4.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Puppet | Firewall Module | unknown | Affected
|
No data.
Red Hat OpenStack Platform 16.1
puppet-firewall-0:3.4.0-1.94f707cgit.el8ost
Fixed · RHSA-2022:8869
Red Hat OpenStack Platform 16.2
puppet-firewall-0:3.4.0-1.94f707cgit.el8ost
Fixed · RHSA-2022:5116
Red Hat OpenStack Platform 13 (Queens)
puppet-firewall
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | puppet-firewall-0:3.4.0-1.94f707cgit.el8ost | Fixed | RHSA-2022:8869 |
| Red Hat OpenStack Platform 16.2 | puppet-firewall-0:3.4.0-1.94f707cgit.el8ost | Fixed | RHSA-2022:5116 |
| Red Hat OpenStack Platform 13 (Queens) | puppet-firewall | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-0675 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2071567 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15761 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0675
- https://puppet.com/security/cve/CVE-2022-0675 x_refsource_MISCVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0675
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0675 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2071567 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15761 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0675 | ||
| https://puppet.com/security/cve/CVE-2022-0675 | x_refsource_MISCVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0675 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data