Medium severity5.3NVD Advisory· Published May 4, 2023· Updated Jun 17, 2026
CVE-2023-1894
CVE-2023-1894
Description
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
Affected products
6cpe:2.3:a:puppet:puppet_enterprise:2021.7.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:puppet:puppet_enterprise:2021.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:puppet:puppet_enterprise:2023.0:*:*:*:*:*:*:*
- (no CPE)range: 2021.7.1
cpe:2.3:a:puppet:puppet_server:7.9.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:puppet:puppet_server:7.9.2:*:*:*:*:*:*:*
- (no CPE)range: <7.9.2
- (no CPE)range: 7.9.2
Patches
Vulnerability mechanics
References
1- www.puppet.com/security/cve/cve-2023-1894-puppet-server-redosnvdVendor Advisory
News mentions
0No linked articles in our index yet.