6.8
CVSSv3

CVE-2015-4100

Published: 21/12/2017 Updated: 24/01/2022
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 5.2 | Exploitability Score: 1.6
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P

Vulnerability Summary

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 3.8.0

puppet puppet enterprise