CVE-2020-7942
published 2020-02-19CVE-2020-7942: Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.82%
53.3th percentile
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Puppet 6.x prior to 6.13.0 Puppet Agent 6.x prior to 6.13.0 Puppet 5.5.x prior to 5.5.19 Puppet Agent 5.5.x prior to 5.5.19 Resolved in: Puppet 6.13.0 Puppet Agent 6.13.0 Puppet 5.5.19 Puppet Agent 5.5.19
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 5.5.19 | 5.5.19 |
| puppet | puppet | >= 5.5.0 < 5.5.19 | 5.5.19 |
| puppet | puppet | >= 6.0.0 < 6.13.0 | 6.13.0 |
| puppet | puppet | >= 6.0.0 < 6.13.0 | 6.13.0 |
| puppet | puppet_agent | — | — |
| puppet | puppet_agent | — | — |
| puppet | puppet_agent | — | — |
| puppet | puppet_agent | — | — |
| puppet | puppet_agent | >= 5.5.0 < 5.5.19 | 5.5.19 |
| puppet | puppet_agent | >= 6.0.0 < 6.13.0 | 6.13.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
puppet: Arbitrary catalog retrieval
vendor_redhat·2020-02-18·CVSS 6.5
CVE-2020-7942 [MEDIUM] CWE-297 puppet: Arbitrary catalog retrieval
puppet: Arbitrary catalog retrieval
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Pu
Debian
CVE-2020-7942: puppet - Previously, Puppet operated on a model that a node with a valid certificate was ...
vendor_debian·2020·CVSS 6.5
CVE-2020-7942 [MEDIUM] CVE-2020-7942: puppet - Previously, Puppet operated on a model that a node with a valid certificate was ...
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Puppet 6.x prior to 6.13.0 Puppet Agent
OSV
Improper Certificate Validation in Puppet
osv·2021-04-13
CVE-2020-7942 [MEDIUM] Improper Certificate Validation in Puppet
Improper Certificate Validation in Puppet
Previously, Puppet operated on the model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior.
GHSA
Improper Certificate Validation in Puppet
ghsa·2021-04-13
CVE-2020-7942 [MEDIUM] CWE-295 Improper Certificate Validation in Puppet
Improper Certificate Validation in Puppet
Previously, Puppet operated on the model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior.
OSV
CVE-2020-7942: Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certi
osv·2020-02-19·CVSS 6.5
CVE-2020-7942 [MEDIUM] CVE-2020-7942: Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certi
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Puppet 6.x prior to 6.13.0 Puppet Agent
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-7942 puppet: Arbitrary catalog retrieval [openstack-rdo]
bugzilla·2020-03-24·CVSS 6.5
CVE-2020-7942 [MEDIUM] CVE-2020-7942 puppet: Arbitrary catalog retrieval [openstack-rdo]
CVE-2020-7942 puppet: Arbitrary catalog retrieval [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Note this issue only affects when running puppet
Bugzilla
CVE-2020-7942 puppet: Arbitrary catalog retrieval [fedora-all]
bugzilla·2020-03-24·CVSS 6.5
CVE-2020-7942 [MEDIUM] CVE-2020-7942 puppet: Arbitrary catalog retrieval [fedora-all]
CVE-2020-7942 puppet: Arbitrary catalog retrieval [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2020-7942 puppet: Arbitrary catalog retrieval [epel-7]
bugzilla·2020-03-24·CVSS 6.5
CVE-2020-7942 [MEDIUM] CVE-2020-7942 puppet: Arbitrary catalog retrieval [epel-7]
CVE-2020-7942 puppet: Arbitrary catalog retrieval [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update' request
Bugzilla
CVE-2020-7942 puppet: Arbitrary catalog retrieval
bugzilla·2020-03-24·CVSS 6.5
CVE-2020-7942 [MEDIUM] CVE-2020-7942 puppet: Arbitrary catalog retrieval
CVE-2020-7942 puppet: Arbitrary catalog retrieval
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior.
References:
https://puppe
2020-02-19
Published