CVSS 3 Base Score:

Posted On:

Assessed Risk Level:
Low

On December 20, 2019, OpenSSL announced several vulnerabilities

Previous versions of Puppet Enterprise shipped with a vulnerable version of OpenSSL. Puppet Enterprise 2018.1.12, 2019.1.4, and 2019.3.0 ship with an updated version of OpenSSL

For more information about these vulnerabilities, please refer to the OpenSSL security announcement (https://www.openssl.org/news/vulnerabilities.html#2019-1551)

Status:

Affected software versions:
  • Puppet Agent 5 versions prior to 5.5.18
  • Puppet Agent 6 versions prior to 6.4.5
  • Puppet Agent 6 versions prior to 6.12.0
  • Puppet Enterprise 2018.1 versions prior to 2018.1.12
  • Puppet Enterprise 2019.1 versions prior to 2019.1.4
  • Puppet Enterprise 2019.2 versions prior to 2019.3.0
  • PE Client Tools 18.1 versions prior to 18.1.13
  • PE Client Tools 19.1 versions prior to 19.1.6
  • PE Client Tools 19.1 versions prior to 19.3.0
  • Bolt versions prior to 1.45.0
  • PDK versions prior to 1.15.0
Resolved in:
  • Puppet Agent 5.5.18
  • Puppet Agent 6.4.5
  • Puppet Agent 6.12.0
  • Puppet Enterprise 2018.1.12
  • Puppet Enterprise 2019.1.4
  • Puppet Enterprise 2019.3.0
  • PE Client Tools 18.1.13
  • PE Client Tools 19.1.6
  • PE Client Tools 19.3.0
  • Bolt 1.45.0
  • PDK 1.15.0