CVE-2020-7942
Description
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the default node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting strict_hostname_checking = true in puppet.conf on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Puppet 6.x prior to 6.13.0 Puppet Agent 6.x prior to 6.13.0 Puppet 5.5.x prior to 5.5.19 Puppet Agent 5.5.x prior to 5.5.19 Resolved in: Puppet 6.13.0 Puppet Agent 6.13.0 Puppet 5.5.19 Puppet Agent 5.5.19
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
puppetRubyGems | >= 6.0.0, < 6.13.0 | 6.13.0 |
puppetRubyGems | < 5.5.19 | 5.5.19 |
Affected products
6cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*range: >=5.5.0,<5.5.19
- (no CPE)range: 5.5.x prior to 5.5.19
cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:*range: >=5.5.0,<5.5.19
- (no CPE)range: 5.5.x prior to 5.5.19
- ghsa-coords2 versionspkg:gem/puppetpkg:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012
>= 6.0.0, < 6.13.0+ 1 more
- (no CPE)range: >= 6.0.0, < 6.13.0
- (no CPE)range: < 3.8.5-15.12.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.