Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-12-21T15:00:00

Updated: 2024-08-06T06:04:02.923Z

Reserved: 2015-05-27T00:00:00

Link: CVE-2015-4100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-12-21T15:29:00.237

Modified: 2022-01-24T16:46:02.597

Link: CVE-2015-4100

cve-icon Redhat

No data.