CVE-2023-5255

Severity CVSS v4.0:
Pending analysis
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
03/10/2023
Last modified:
20/11/2025

Description

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:puppet:puppet_enterprise:2023.3:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_server:8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:puppet:puppet_server:8.2.1:*:*:*:*:*:*:*