The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-08-12T23:00:00

Updated: 2017-11-14T16:57:01

Reserved: 2014-05-07T00:00:00


Link: CVE-2014-3251

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-08-12T23:55:03.643

Modified: 2019-07-10T18:10:47.430


Link: CVE-2014-3251

JSON object: View

cve-icon Redhat Information

No data.

CWE