VDB

CVE-2021-27018

CVE-2021-27018 PUBLISHED CVSS 7.5 HIGH

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.

EPSS 0.54% · 43.5th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.54%
43.5th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSpuppet0, 5.5.10-4ubuntu3, 5.4.0-2ubuntu3
Ubuntu:22.04:LTSpuppet0, 5.5.22-4, 5.5.22-4ubuntu0.2
Ubuntu:14.04:LTSpuppet3.4.3-1ubuntu1.1, 3.4.3-1ubuntu1.2, 3.4.3-1ubuntu1.3
Ubuntu:18.04:LTSpuppet5.4.0-2ubuntu3, 0, 4.10.4-2ubuntu1
Ubuntu:Pro:16.04:LTSpuppet3.8.4-1ubuntu1, 3.7.2-5ubuntu2, 0

Timeline

  • Aug 30, 2021 CVE Published
  • Aug 31, 2021 EPSS Score
  • Oct 29, 2021 EPSS Score
  • Dec 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 23, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 22, 2022 EPSS Score
  • Jun 20, 2022 EPSS Score
  • Aug 18, 2022 EPSS Score
  • Oct 16, 2022 EPSS Score
  • Dec 13, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›