CVE Database
/

CVE-2023-1894

Back to search

CVE-2023-1894

Published: May 4, 2023

Modified: Jan 29, 2025

PUBLISHED

Description

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

VendorProductVersions

Puppet

Puppet Enterprise

affected
2021.7.1 - < 2021.7.3
affected
2023.0.0 - < 2023.1.0

Puppet

Puppet Server

affected
7.9.2 - < 7.11.0
affected
7.9.2 - < 8.0.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now