CVE-2014-3251Race Condition in Enterprise

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 92.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 14

Description

The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.

CVSS vector

AV:L/AC:M/C:P/I:P/A:PExploitability: 3.4 | Impact: 6.4

Affected Packages2 packages

Debianpuppet/mcollective< 2.6.0+dfsg-1+1

🔴Vulnerability Details

3
GHSA
GHSA-q495-m6p3-c645: The MCollective aes_security plugin, as used in Puppet Enterprise before 32022-05-14
CVEList
CVE-2014-3251: The MCollective aes_security plugin, as used in Puppet Enterprise before 32014-08-12
OSV
CVE-2014-3251: The MCollective aes_security plugin, as used in Puppet Enterprise before 32014-08-12

📋Vendor Advisories

2
Red Hat
mcollective: aes_security.rb file creation vulnerability2014-07-15
Debian
CVE-2014-3251: mcollective - The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 a...2014

💬Community

5
Bugzilla
CVE-2014-3251 mcollective: aes_security.rb file creation vulnerability [fedora-all]2014-11-08
Bugzilla
CVE-2014-3251 mcollective: aes_security.rb file creation vulnerability [epel-7]2014-11-08
Bugzilla
CVE-2014-3251 mcollective: aes_security.rb file creation vulnerability [epel-6]2014-11-08
Bugzilla
CVE-2014-3251 mcollective: aes_security.rb file creation vulnerability [epel-5]2014-11-08
Bugzilla
CVE-2014-3251 mcollective: aes_security.rb file creation vulnerability2014-06-06
CVE-2014-3251 — Race Condition in Puppet Enterprise | cvebase