CVE-2017-2294
published 2017-07-05CVE-2017-2294: Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.16%
65.0th percentile
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet_enterprise | <= 2016.4.3 | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-2294: puppet - Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MColl...
vendor_debian·2017·CVSS 7.5
CVE-2017-2294 [HIGH] CVE-2017-2294: puppet - Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MColl...
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.
Scope: local
bullseye: resolved
GHSA
GHSA-p5c4-h8f6-v559: Versions of Puppet Enterprise prior to 2016
ghsa_unreviewed·2022-05-13
CVE-2017-2294 [HIGH] CWE-200 GHSA-p5c4-h8f6-v559: Versions of Puppet Enterprise prior to 2016
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-07-05
Published