Vulnerabilities > CVE-2023-1894 - Unspecified vulnerability in Puppet Enterprise and Puppet Server

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
network
low complexity
puppet

Summary

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

Vulnerable Configurations

Part Description Count
Application
Puppet
3