CVE Database
/

CVE-2018-6517

Back to search

CVE-2018-6517

Published: Mar 17, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride.

VendorProductVersions

Puppet

Chloride

affected
prior to 0.3.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now