Vulnerability Description
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Puppet | Remediate | < 2.0.1 |
Related Weaknesses (CWE)
References
- https://puppet.com/security/cve/CVE-2021-27018Vendor Advisory
- https://puppet.com/security/cve/CVE-2021-27018Vendor Advisory
FAQ
What is CVE-2021-27018?
CVE-2021-27018 is a vulnerability with a CVSS score of 7.5 (HIGH). The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue onl...
How severe is CVE-2021-27018?
CVE-2021-27018 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27018?
Check the references section above for vendor advisories and patch information. Affected products include: Puppet Remediate.