CVE Vulnerabilities

CVE-2012-3867

Published: Aug 06, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet2.6.0 (including)2.6.0 (including)
PuppetPuppet2.6.1 (including)2.6.1 (including)
PuppetPuppet2.6.2 (including)2.6.2 (including)
PuppetPuppet2.6.3 (including)2.6.3 (including)
PuppetPuppet2.6.4 (including)2.6.4 (including)
PuppetPuppet2.6.5 (including)2.6.5 (including)
PuppetPuppet2.6.6 (including)2.6.6 (including)
PuppetPuppet2.6.7 (including)2.6.7 (including)
PuppetPuppet2.6.8 (including)2.6.8 (including)
PuppetPuppet2.6.9 (including)2.6.9 (including)
PuppetPuppet2.6.10 (including)2.6.10 (including)
PuppetPuppet2.6.11 (including)2.6.11 (including)
PuppetPuppet2.6.12 (including)2.6.12 (including)
PuppetPuppet2.6.13 (including)2.6.13 (including)
PuppetPuppet2.6.14 (including)2.6.14 (including)
PuppetPuppet2.6.15 (including)2.6.15 (including)
PuppetPuppet2.7.2 (including)2.7.2 (including)
PuppetPuppet2.7.3 (including)2.7.3 (including)
PuppetPuppet2.7.4 (including)2.7.4 (including)
PuppetPuppet2.7.5 (including)2.7.5 (including)
PuppetPuppet2.7.6 (including)2.7.6 (including)
PuppetPuppet2.7.7 (including)2.7.7 (including)
PuppetPuppet2.7.8 (including)2.7.8 (including)
PuppetPuppet2.7.9 (including)2.7.9 (including)
PuppetPuppet2.7.10 (including)2.7.10 (including)
PuppetPuppet2.7.11 (including)2.7.11 (including)
PuppetPuppet2.7.12 (including)2.7.12 (including)
PuppetPuppet2.7.13 (including)2.7.13 (including)
PuppetPuppet2.7.14 (including)2.7.14 (including)
PuppetPuppet2.7.16 (including)2.7.16 (including)
PuppetPuppet2.7.17 (including)2.7.17 (including)
PuppetPuppetlabs*2.6.16 (including)
PuppetPuppetlabs2.7.0 (including)2.7.0 (including)
PuppetPuppetlabs2.7.1 (including)2.7.1 (including)
CloudForms for RHEL 6RedHatconverge-ui-devel-0:1.0.4-1.el6cf*
CloudForms for RHEL 6RedHatpuppet-0:2.6.17-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-actionpack-1:3.0.10-10.el6cf*
CloudForms for RHEL 6RedHatrubygem-activerecord-1:3.0.10-6.el6cf*
CloudForms for RHEL 6RedHatrubygem-activesupport-1:3.0.10-4.el6cf*
CloudForms for RHEL 6RedHatrubygem-chunky_png-0:1.2.0-3.el6cf*
CloudForms for RHEL 6RedHatrubygem-compass-0:0.11.5-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-compass-960-plugin-0:0.10.4-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-delayed_job-0:2.1.4-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-ldap_fluff-0:0.1.3-1.el6_3*
CloudForms for RHEL 6RedHatrubygem-mail-0:2.3.0-3.el6cf*
CloudForms for RHEL 6RedHatrubygem-net-ldap-0:0.1.1-3.el6cf*
PuppetUbuntudevel*
PuppetUbuntuhardy*
PuppetUbuntulucid*
PuppetUbuntunatty*
PuppetUbuntuoneiric*
PuppetUbuntuprecise*
PuppetUbuntuupstream*

References