VDB
CVE-2011-3872
CVE-2011-3872
PUBLISHED
CVSS 2.5999999046325684 LOW
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
EPSS 2.78% · 86.4th percentile
Risk Scores
CVSS v2.0
2.5999999046325684
EPSS Score
2.78%
86.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| puppetlabs | puppet | 2.7.1, 2.7.0 |
| puppet | puppet | 2.6.9, 2.6.11, 2.7.2 |
| puppet | puppet_enterprise | 1.2.1, 1.2.3, 1.2.0 |
| puppetlabs | puppet_enterprise_users | 1.0, 1.1 |
| n/a | n/a | * |
Exploit Intelligence
- Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872) (github-poc)
- Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872) (github-poc)
- Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872) (github-poc)
- Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872) (github-poc)
- 46934 (circl)
- https://puppet.com/security/cve/cve-2011-3872 (circl)
- 46550 (circl)
- http://groups.google.com/group/puppet-announce/browse_thread/thread/e7edc3a71348f3e1 (circl)
- 50356 (circl)
- 46964 (circl)
…and 5 more exploits
Timeline
- Oct 27, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 46550 third-party-advisory
- USN-1238-2 vendor-advisory
- http://puppetlabs.com/blog/important-security-announcement-altnames-vulnerability/ url
- puppet-x509-spoofing(70970) vdb
- 46578 third-party-advisory
- https://puppet.com/security/cve/cve-2011-3872 url
- 46934 third-party-advisory
- http://groups.google.com/group/puppet-announce/browse_thread/thread/e7edc3a71348f3e1 url
- 50356 vdb
- 46964 third-party-advisory
- USN-1238-1 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-3872 advisory
- http://puppetlabs.com/blog/important-security-announcement-altnames-vulnerability url