CVE-2014-3250
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-3250
Vendor advisory: cve@mitre.org — https://puppet.com/security/cve/CVE-2014-3250
Vendor advisory: cve@mitre.org — https://bugzilla.redhat.com/show_bug.cgi?id=1101347
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bullseye | fixed | 3.7.0-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| puppet | puppet | {"endExcluding":"3.6.2"} | 3.6.2 |
| apache | http_server | 2.4.0 | |
References
CWEs
CWE-295
Verify integrity in audit chain (admin only). AS-IS.