CVE-2015-4100

medium
Published 2017-12-21 · Modified 2026-05-13
CVSS v3
6.8
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS v2
4.9
VIR risk
6.8

Description

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

Predictions

Exploit likelihood
77%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-4100

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://puppet.com/security/cve/CVE-2015-4100

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed0

Application impact

VendorProductVersionsFixed
puppetpuppet_enterprise{"startIncluding":"3.7.0","endIncluding":"3.7.2"}
puppetpuppet_enterprise3.8.0

References

CWEs

CWE-295

Verify integrity in audit chain (admin only). AS-IS.