CVE-2012-3867
published 2012-08-06CVE-2012-3867: lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.45%
82.6th percentile
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | puppet | < puppet 2.7.18-1 (bullseye) | puppet 2.7.18-1 (bullseye) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
osv·2017-10-24
CVE-2012-3867 [MEDIUM] Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
`lib/puppet/ssl/certificate_authority.rb` in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
GHSA
Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
ghsa·2017-10-24
CVE-2012-3867 [MEDIUM] Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
Pupper does not properly restrict characters in Common Name field of Certificate Signing Request
`lib/puppet/ssl/certificate_authority.rb` in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
OSV
CVE-2012-3867: lib/puppet/ssl/certificate_authority
osv·2012-08-06·CVSS 4.3
CVE-2012-3867 [MEDIUM] CVE-2012-3867: lib/puppet/ssl/certificate_authority
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-07-12·CVSS 4.0
CVE-2012-3864 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in Puppet.
It was discovered that Puppet incorrectly handled certain HTTP GET
requests. An attacker could use this flaw with a valid client certificate
to retrieve arbitrary files from the Puppet primary server.
(CVE-2012-3864)
It was discovered that Puppet incorrectly handled Delete requests. If a
Puppet primary server were reconfigured to allow the "Delete" method, an
attacker on an authenticated host could use this flaw to delete arbitrary
files from the Puppet server, leading to a denial of service.
(CVE-2012-3865)
It was discovered that Puppet incorrectly set file permissions on the
last_run_report.yaml file. An attacker could use this flaw to access
sensitive information. This issue only affected Ubuntu 11.
Red Hat
puppet: insufficient validation of agent names in CN of SSL certificate requests
vendor_redhat·2012-07-10·CVSS 4.3
CVE-2012-3867 [MEDIUM] puppet: insufficient validation of agent names in CN of SSL certificate requests
puppet: insufficient validation of agent names in CN of SSL certificate requests
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-3867: puppet - lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before...
vendor_debian·2012·CVSS 4.3
CVE-2012-3867 [MEDIUM] CVE-2012-3867: puppet - lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before...
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
Scope: local
bullseye: resolved (fixed in 2.7.18-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3867 puppet various flaws [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&
Bugzilla
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
bugzilla·2012-07-11·CVSS 4.0
CVE-2012-3864 [MEDIUM] CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
CVE-2012-3864 CVE-2012-3865 CVE-2012-3866 CVE-2012-3867 puppet various flaws [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2012-3867 puppet: insufficient validation of agent names in CN of SSL certificate requests
bugzilla·2012-07-11·CVSS 4.3
CVE-2012-3867 [MEDIUM] CVE-2012-3867 puppet: insufficient validation of agent names in CN of SSL certificate requests
CVE-2012-3867 puppet: insufficient validation of agent names in CN of SSL certificate requests
From puppet labs: CVE-2012-3867 (Insufficient input validation)
A bug in Puppet 2.6.16 and 2.7.17 uses insufficient input validation for agent
certificate names.
An attacker can trick the administrator into signing an attacker’s certificate
rather than the intended one by constructing specially crafted certificate
requests containing specific ANSI control sequences. It is possible to use the
sequences to rewrite the order of text displayed to an administrator such that
display of an invalid certificate and valid certificate are transposed. If the
administrator signs the attacker’s certificate, the attacker can then
man-in-the-middle the deployment’s agent nodes.
Resolved in Puppet 2.6.17, 2.7
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3867/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839158https://github.com/puppetlabs/puppet/commit/dfedaa5fa841ccf335245a748b347b7c7c236640https://github.com/puppetlabs/puppet/commit/f3419620b42080dad3b0be14470b20a972f13c50http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-07/msg00036.htmlhttp://puppetlabs.com/security/cve/cve-2012-3867/http://secunia.com/advisories/50014http://www.debian.org/security/2012/dsa-2511http://www.ubuntu.com/usn/USN-1506-1https://bugzilla.redhat.com/show_bug.cgi?id=839158https://github.com/puppetlabs/puppet/commit/dfedaa5fa841ccf335245a748b347b7c7c236640https://github.com/puppetlabs/puppet/commit/f3419620b42080dad3b0be14470b20a972f13c50
2012-08-06
Published