Bug 26530 - puppet new security issues CVE-2018-11751 and CVE-2020-794[23]
Summary: puppet new security issues CVE-2018-11751 and CVE-2020-794[23]
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-04-23 20:53 CEST by David Walser
Modified: 2021-07-01 18:23 CEST (History)
2 users (show)

See Also:
Source RPM: puppet-6.0.3-3.mga8.src.rpm
CVE: CVE-2020-7942
Status comment: Fixed upstream in 6.13.0


Attachments

Description David Walser 2020-04-23 20:53:48 CEST
SUSE has issued an advisory on April 21:
http://lists.suse.com/pipermail/sle-security-updates/2020-April/006721.html

The issue is fixed upstream in 6.13.0.

It looks like SUSE made a patch to highlight and issue a warning for a configuration that needs to be changed to mitigate this.

Mageia 7 is also affected.
David Walser 2020-04-23 21:32:19 CEST

Whiteboard: (none) => MGA7TOO

Comment 1 Lewis Smith 2020-04-23 21:43:57 CEST
Puppet has no registered maintainer, nor any consistent committer. Hence assigning this globally.

Assignee: bugsquad => pkg-bugs

Comment 2 David Walser 2020-10-29 01:58:52 CET
RedHat has issued an advisory on October 27:
https://access.redhat.com/errata/RHSA-2020:4366

It fixes this issue and two others in Puppet, CVE-2018-11751 (fixed upstream in 6.4.0) and CVE-2020-7943 (fixed upstream in 6.10.1).  For the latter, RedHat thinks they identified the commit that fixed it:
https://bugzilla.redhat.com/show_bug.cgi?id=1828486#c4

Severity: normal => critical
Summary: puppet new security issue CVE-2020-7942 => puppet new security issues CVE-2018-11751 and CVE-2020-794[23]

Zombie Ryushu 2020-12-29 11:45:37 CET

CC: (none) => zombie_ryushu
CVE: (none) => CVE-2020-7942
URL: (none) => https://nvd.nist.gov/vuln/detail/CVE-2020-7942

Comment 3 Nicolas Lécureuil 2020-12-30 11:20:02 CET
we updated cauldron to puppet 7.1.0

CC: (none) => mageia
Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

David Walser 2020-12-30 11:44:19 CET

Status comment: (none) => Fixed upstream in 6.13.0

Comment 4 David Walser 2021-07-01 18:23:07 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.