CVE-2021-27025 - log back

CVE-2021-27025 edited at 10 Nov 2021 00:01:36
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A security issue was discovered in Puppet before version 7.12.1 where the agent may silently ignore Augeas settings or may be vulnerable to a denial of service condition prior to the first pluginsync.
References
+ https://puppet.com/security/cve/CVE-2021-27025
+ https://puppet.com/docs/puppet/7/release_notes_puppet.html#release_notes_puppet_7-12-1
+ https://tickets.puppetlabs.com/browse/PUP-11209
+ https://github.com/puppetlabs/puppet/commit/0e189e9988c4969280134d043b871851928caa41
CVE-2021-27025 created at 09 Nov 2021 23:51:24