VulnerabilityModified
CVE-2021-27018
This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.
HIGH 7.5EPSS 0.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- puppet/remediate
- Source
- security@puppet.com
References
- https://puppet.com/security/cve/CVE-2021-27018Vendor Advisory
- https://puppet.com/security/cve/CVE-2021-27018Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.