CVE-2013-1654Puppet vulnerability

10 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 14

Description

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Debianpuppet/puppet< 2.7.18-3
NVDpuppet/puppet16 versions+15
NVDpuppetlabs/puppet4 versions+3

Also affects: Ubuntu Linux 11.10, 12.04, 12.10

🔴Vulnerability Details

3
GHSA
GHSA-53gg-mm53-pphh: Puppet 22022-05-14
OSV
CVE-2013-1654: Puppet 22013-03-20
CVEList
CVE-2013-1654: Puppet 22013-03-20

📋Vendor Advisories

3
Ubuntu
Puppet vulnerabilities2013-03-12
Red Hat
Puppet: SSL protocol downgrade2013-03-12
Debian
CVE-2013-1654: puppet - Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x b...2013

💬Community

3
Bugzilla
CVE-2013-1640 CVE-2013-1652 CVE-2013-1654 CVE-2013-2274 CVE-2013-2275 puppet various flaws [epel-all]2013-03-12
Bugzilla
CVE-2013-1640 CVE-2013-1652 CVE-2013-1653 CVE-2013-1654 CVE-2013-1655 CVE-2013-2275 puppet various flaws [fedora-all]2013-03-12
Bugzilla
CVE-2013-1654 Puppet: SSL protocol downgrade2013-03-10
CVE-2013-1654 — Puppet vulnerability | cvebase