{"api_version":"1","generated_at":"2026-04-22T21:27:17+00:00","cve":"CVE-2021-27018","urls":{"html":"https://cve.report/CVE-2021-27018","api":"https://cve.report/api/cve/CVE-2021-27018.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-27018","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-27018"},"summary":{"title":"CVE-2021-27018","description":"The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.","state":"PUBLIC","assigner":"security@puppet.com","published_at":"2021-08-30 18:15:00","updated_at":"2021-09-07 18:29:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://puppet.com/security/cve/CVE-2021-27018","name":"https://puppet.com/security/cve/CVE-2021-27018","refsource":"MISC","tags":[],"title":"CVE-2021-27018 - Incorrect Certificate Validation | Puppet","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-27018","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27018","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"27018","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"puppet","cpe5":"remediate","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-27018","ASSIGNER":"security@puppet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Puppet Remediate","version":{"version_data":[{"version_value":"Affects Puppet Remediate prior to 2.0, resolved in 2.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Verification of Cryptographic Signature"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://puppet.com/security/cve/CVE-2021-27018","url":"https://puppet.com/security/cve/CVE-2021-27018"}]},"description":{"description_data":[{"lang":"eng","value":"The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source."}]}},"nvd":{"publishedDate":"2021-08-30 18:15:00","lastModifiedDate":"2021-09-07 18:29:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:puppet:remediate:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"27018","Ordinal":"202102","Title":"CVE-2021-27018","CVE":"CVE-2021-27018","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"27018","Ordinal":"1","NoteData":"The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"27018","Ordinal":"2","NoteData":"2021-08-30","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"27018","Ordinal":"3","NoteData":"2021-08-30","Type":"Other","Title":"Modified"}]}}}