CVE-2018-11751

Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.
References
Link Resource
https://puppet.com/security/cve/CVE-2018-11751 Vendor Advisory
Configurations

Configuration 1

cpe:2.3:a:puppet:puppet_server:*:*:*:*:*:*:*:*

Information

Published : 2019-12-16 10:15

Updated : 2020-04-07 01:10


NVD link : CVE-2018-11751

Mitre link : CVE-2018-11751

Products Affected
No products.
CWE
CWE-295

Improper Certificate Validation