CVE-2014-3250
published 2017-12-11CVE-2014-3250: The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain…
PriorityP429medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.89%
55.5th percentile
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 3.7.0-1 (bullseye) | puppet 3.7.0-1 (bullseye) |
| puppet | puppet | < 3.6.2 | 3.6.2 |
| puppet | puppet | >= 0 < 3.7.0-1 | 3.7.0-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
puppet: certificates could be honored even when revoked
vendor_redhat·2014-06-10·CVSS 6.5
CVE-2014-3250 [MEDIUM] puppet: certificates could be honored even when revoked
puppet: certificates could be honored even when revoked
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Statement: Not vulnerable. This issue did not affect the versions of puppet as shipped with Red Hat Subscription Asset Manager 1.3 as they did not include puppet-server.
Package: puppet (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: puppet (Red Hat OpenStack Platform 3) - Will not fix
Package: puppet (Red Hat OpenStack Platform 4) - Will not fix
Package: puppet (Red Hat Satellite 6) - Affected
Package: ruby193-puppet (Red Hat Subscription Asset Man
Debian
CVE-2014-3250: puppet - The default vhost configuration file in Puppet before 3.6.2 does not include the...
vendor_debian·2014·CVSS 6.5
CVE-2014-3250 [MEDIUM] CVE-2014-3250: puppet - The default vhost configuration file in Puppet before 3.6.2 does not include the...
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Scope: local
bullseye: resolved (fixed in 3.7.0-1)
GHSA
GHSA-mmpq-gqvm-78gf: The default vhost configuration file in Puppet before 3
ghsa_unreviewed·2022-05-14
CVE-2014-3250 [MEDIUM] CWE-295 GHSA-mmpq-gqvm-78gf: The default vhost configuration file in Puppet before 3
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
OSV
CVE-2014-3250: The default vhost configuration file in Puppet before 3
osv·2017-12-11·CVSS 6.5
CVE-2014-3250 [MEDIUM] CVE-2014-3250: The default vhost configuration file in Puppet before 3
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3250 puppet: certificates could be honored even when revoked [fedora-all]
bugzilla·2014-06-11·CVSS 6.5
CVE-2014-3250 [MEDIUM] CVE-2014-3250 puppet: certificates could be honored even when revoked [fedora-all]
CVE-2014-3250 puppet: certificates could be honored even when revoked [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mult
Bugzilla
CVE-2014-3250 puppet: certificates could be honored even when revoked
bugzilla·2014-05-27·CVSS 6.5
CVE-2014-3250 [MEDIUM] CVE-2014-3250 puppet: certificates could be honored even when revoked
CVE-2014-3250 puppet: certificates could be honored even when revoked
Upstream reports:
""
In Apache 2.4, SSLCARevocationCheck directive was added to mod_ssl,
which defaults it to none and must be explicitly configured. This
setting enables checking of a certificate revocation list. The default
Puppet master vhost config shipped with Puppet does not include this
setting. If a Puppet master is set up to run with Apache 2.4, and this
default vhost configuration file is used, the Puppet master will
continue to honor a host's certificate even after it is revoked.
""
Acknowledgements:
Red Hat would like to thank Puppet Labs for reporting this issue.
Discussion:
Created attachment 899367
upstream patch
---
Created attachment 902402
revised upstream patch
---
(In reply to Murray McAllis
2017-12-11
Published