CVE-2018-11749 Information
Feb 14, 2021
cve
Description
When users are configured to use startTLS with RBAC LDAP at login time the user’s credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3 2017.3.9 and 2016.4.14 and is fixed in Puppet Enterprise 2018.1.4 2017.3.10 and 2016.4.15. It scored an 8.5 CVSS score.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://puppet.com/security/cve/cve-2018-11749
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: