CVE-2021-27025
published 2021-11-18CVE-2021-27025: A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the…
PriorityP429medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.15%
63.3th percentile
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| debian | puppet-agent | — | — |
| fedoraproject | fedora | — | — |
| puppet | puppet | >= 0 < 6.25.1 | 6.25.1 |
| puppet | puppet | >= 2021.0.0 < 2021.4.0 | 2021.4.0 |
| puppet | puppet | >= 7.0.0 < 7.12.1 | 7.12.1 |
| puppet | puppet_agent | < 6.25.1 | 6.25.1 |
| puppet | puppet_agent | 5.5.0 – 5.5.22 | — |
| puppet | puppet_agent | >= 7.0.0 < 7.12.1 | 7.12.1 |
| puppet | puppet_enterprise | < 2019.8.9 | 2019.8.9 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Silent Configuration Failure in Puppet Agent
ghsa·2021-12-02
CVE-2021-27025 [MEDIUM] Silent Configuration Failure in Puppet Agent
Silent Configuration Failure in Puppet Agent
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
OSV
Silent Configuration Failure in Puppet Agent
osv·2021-12-02
CVE-2021-27025 [MEDIUM] Silent Configuration Failure in Puppet Agent
Silent Configuration Failure in Puppet Agent
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
OSV
CVE-2021-27025: A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior
osv·2021-11-18·CVSS 6.5
CVE-2021-27025 [MEDIUM] CVE-2021-27025: A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
Red Hat
puppet: silent configuration failure in agent
vendor_redhat·2021-11-09·CVSS 6.5
CVE-2021-27025 [MEDIUM] CWE-665 puppet: silent configuration failure in agent
puppet: silent configuration failure in agent
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
A configuration flaw was found in Puppet Agent where the agent silently ignores Augeas settings. This flaw allows a network attacker to cause a denial of service before the first pluginsync. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: puppet (Red Hat Op
Debian
CVE-2021-27025: puppet - A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas...
vendor_debian·2021·CVSS 6.5
CVE-2021-27025 [MEDIUM] CVE-2021-27025: puppet - A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas...
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/https://puppet.com/security/cve/cve-2021-27025https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/https://puppet.com/security/cve/cve-2021-27025
2021-11-18
Published