CVE-2023-1894
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
Affected (3)
Products: Puppet: Puppet Enterprise, Puppet Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2021.7.1 | |
| Version 7.9.2 |
References (2)
Source: security@puppet.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.