RubySec

Providing security resources for the Ruby community

CVE-2021-27025 (puppet): Silent Configuration Failure in Puppet Agent

ADVISORIES

GEM

puppet

SEVERITY

CVSS v3.x: 6.5 (Medium)

PATCHED VERSIONS

  • ~> 6.25.1
  • >= 7.12.1

DESCRIPTION

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first ‘pluginsync’.