CVE-2023-1894
published 2023-05-04CVE-2023-1894: A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted…
medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppetserver 7.9.5-2 (bookworm) | puppetserver 7.9.5-2 (bookworm) |
| debian | puppetserver | < puppetserver 7.9.5-2 (bookworm) | puppetserver 7.9.5-2 (bookworm) |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | >= 2021.7.1 < 2021.7.3 | 2021.7.3 |
| puppet | puppet_enterprise | >= 2023.0.0 < 2023.1.0 | 2023.1.0 |
| puppet | puppet_server | — | — |
| puppet | puppet_server | >= 7.9.2 < 7.11.0 | 7.11.0 |
| puppet | puppet_server | >= 7.9.2 < 8.0.0 | 8.0.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM