CVE-2011-3848
Publication date 28 September 2011
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.
References
Related Ubuntu Security Notices (USN)
- USN-1217-1
- Puppet vulnerability
- 29 September 2011