CVE-2017-2294
Summary
| CVE | CVE-2017-2294 |
|---|---|
| State | PUBLISHED |
| Assigner | puppet |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-07-05 15:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-200 | client private keys insufficiently protected
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Puppet | Puppet Enterprise | 2016.5.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2016.5.2 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2017.1.0 | All | All | All |
| Application | Puppet | Puppet Enterprise | 2017.1.1 | All | All | All |
| Application | Puppet | Puppet Enterprise | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Puppet | Puppet Enterprise | affected PE prior to 2016.4.5 or 2017.2.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-2294 - MCollective Private Keys Visible In PuppetDB | Puppet.com | af854a3a-2127-422b-91ae-364da2661108 | puppet.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.