CVE Vulnerabilities

CVE-2014-3250

Improper Certificate Validation

Published: Dec 11, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet*3.6.2 (excluding)
PuppetUbuntuesm-infra-legacy/trusty*
PuppetUbuntutrusty*
PuppetUbuntutrusty/esm*
PuppetUbuntuupstream*

Potential Mitigations

References