CVE-2021-27025

Public on 2021-11-18
Modified on 2024-05-02
Description
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Emr-puppet Extra emr-puppet 2023-09-06 ALAS2EMR-PUPPET-2023-001 Fixed
Amazon Linux 1 puppet Not Affected
Amazon Linux 1 puppet3 Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NVD CVSSv2 4.0 AV:N/AC:L/Au:S/C:N/I:N/A:P
NVD CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H