CVE-2021-27025

Name
CVE-2021-27025
Description
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://puppet.com/security/cve/cve-2021-27025
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:puppet:puppet:*:*:*:*:enterprise:*:*:* puppet >= None < 2019.8.9
cpe:2.3:a:puppet:puppet:*:*:*:*:enterprise:*:*:* puppet >= 2021.0.0 < 2021.4.0
cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:* puppet_agent >= 5.5.0 <= 5.5.22
cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:* puppet_agent >= None < 6.25.1
cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:* puppet_agent >= 7.0.0 < 7.12.1
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:* puppet_enterprise >= None < 2019.8.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status