CVE-2021-27025Improper Initialization in Puppet

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 32.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateDec 2

Description

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDpuppet/puppet_agent7.0.07.12.1+2
NVDpuppet/puppet2021.0.02021.4.0
RubyGemspuppet/puppet7.0.07.12.1+1
NVDpuppet/puppet_enterprise< 2019.8.9

Also affects: Fedora 35

🔴Vulnerability Details

4
GHSA
Silent Configuration Failure in Puppet Agent2021-12-02
OSV
Silent Configuration Failure in Puppet Agent2021-12-02
CVEList
CVE-2021-27025: A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior2021-11-18
OSV
CVE-2021-27025: A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior2021-11-18

📋Vendor Advisories

2
Red Hat
puppet: silent configuration failure in agent2021-11-09
Debian
CVE-2021-27025: puppet - A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas...2021
CVE-2021-27025 — Improper Initialization in Puppet | cvebase