Vulnerability Description
Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir` parameter, a default will be provided for the `ssl_certs_dir` that will trust certificates from any of the system-trusted certificate authorities. This did not affect FreeBSD.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Puppet | Puppetlabs-Apache | 0.0.4 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100859Third Party AdvisoryVDB Entry
- https://puppet.com/security/cve/CVE-2017-2299Vendor Advisory
- http://www.securityfocus.com/bid/100859Third Party AdvisoryVDB Entry
- https://puppet.com/security/cve/CVE-2017-2299Vendor Advisory
FAQ
What is CVE-2017-2299?
CVE-2017-2299 is a vulnerability with a CVSS score of 7.5 (HIGH). Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir...
How severe is CVE-2017-2299?
CVE-2017-2299 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2299?
Check the references section above for vendor advisories and patch information. Affected products include: Puppet Puppetlabs-Apache.