Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in puppet-agent. Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release. |
| Title | puppet-agent: Deserialization of untrusted data | Deserialization of untrusted data |
| References |
|
Status: PUBLISHED
Assigner: Perforce
Published: 2025-02-07T19:28:45.531Z
Updated: 2025-02-07T19:46:31.091Z
Reserved: 2021-02-09T22:41:26.424Z
Link: CVE-2021-27017
Updated: 2025-02-07T19:46:24.940Z
Status : Received
Published: 2025-02-07T20:15:31.983
Modified: 2025-02-07T20:15:31.983
Link: CVE-2021-27017