CVE Vulnerabilities

CVE-2023-1894

Inefficient Regular Expression Complexity

Published: May 04, 2023 | Modified: Jan 29, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
Puppet_enterprisePuppet2021.7.1 (including)2021.7.1 (including)
Puppet_enterprisePuppet2023.0 (including)2023.0 (including)
Puppet_serverPuppet7.9.2 (including)7.9.2 (including)
Red Hat Satellite 6.14 for RHEL 8RedHatpuppetserver-0:7.11.0-1.el8sat*
Red Hat Satellite 6.14 for RHEL 8RedHatpuppetserver-0:7.11.0-1.el8sat*
PuppetUbuntubionic*
PuppetUbuntuesm-apps/xenial*
PuppetUbuntufocal*
PuppetUbuntukinetic*
PuppetUbuntutrusty*
PuppetUbuntutrusty/esm*
PuppetUbuntuxenial*
PuppetserverUbuntulunar*
PuppetserverUbuntumantic*
PuppetserverUbuntuoracular*
PuppetserverUbuntuplucky*
PuppetserverUbuntutrusty*
PuppetserverUbuntuxenial*

Potential Mitigations

References