Beveiligingsadvies

CVE-2011-3848

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2011-10-27 20:00:00
Laatst bijgewerkt 2024-08-06 23:46:03
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.