https://www.puppet.com/community logo
Join Slack
Powered by
# security
  • j

    Jeremy Mill

    07/15/2022, 4:31 PM
    Hi all, we've published https://puppet.com/security/cve/CVE-2022-2394 today, you should update bolt to version 3.24.0 which was released late last month: https://github.com/puppetlabs/bolt/blob/main/CHANGELOG.md#bolt-3240-2022-06-29
    🙌 1
  • s

    Slackbot

    01/09/2023, 6:48 PM
    This message was deleted.
    b
    w
    • 3
    • 3
  • t

    tvaughan

    01/18/2023, 9:03 PM
    https://thehackernews.com/2023/01/git-users-urged-to-update-software-to.html
  • b

    binford2k

    02/23/2023, 5:25 PM
    Hey y'all. Just wanted to let you know that the improved CVE listing page has launched. You'll see a big yellow button linking to it on https://www.puppet.com/security now.
  • j

    John O'Connor

    04/14/2023, 5:17 PM
    @John O'Connor has left the channel
  • b

    boats

    06/13/2023, 10:04 AM
    @boats has left the channel
  • i

    Igar Volan

    08/30/2023, 1:31 PM
    @Igar Volan has left the channel
  • y

    Yorokobi

    10/17/2023, 2:36 PM
    @Yorokobi has left the channel
  • s

    Slackbot

    10/30/2023, 5:24 PM
    This message was deleted.
    c
    • 2
    • 1
  • h

    Hawson

    10/30/2023, 5:42 PM
    Thanks.
  • a

    Anudeep Seri

    11/15/2023, 4:48 PM
    Hello Team, We received a curl vulnerability (CVE-2022-43552) for Puppet open source 7.21. Is there any patch release to fix the issue to downgrade curl version below 7.69 or above 8.4.0?
  • c

    CVQuesty

    11/15/2023, 4:51 PM
    the latest 8.x solved the curl issue, I think. I seem to remember discussions going on here last week.
  • c

    CVQuesty

    11/15/2023, 4:52 PM
    https://www.puppet.com/docs/puppet/8/release_notes_puppet#security_fixes_puppet_x-8-3-0-PA-5848
  • a

    Anudeep Seri

    11/15/2023, 5:23 PM
    rpm -ivh puppet-agent-8.3.1-1.el7.x86_64.rpm warning: puppet-agent-8.3.1-1.el7.x86_64.rpm: Header V4 RSA/SHA512 Signature, key ID 9e61ef26: NOKEY Verifying... ################################# [100%] Preparing... ################################# [100%] Updating / installing... 1:puppet-agent-8.3.1-1.el7 ################################# [100%] [root@xxxxx tmp]# /opt/puppetlabs/puppet/bin/curl --version curl 7.88.1 (x86_64-pc-linux-gnu) libcurl/7.88.1 OpenSSL/3.0.11 zlib/1.2.11 Release-Date: 2023-02-20 Protocols: dict file ftp ftps gopher gophers http https imap imaps mqtt pop3 pop3s rtsp smtp smtps telnet tftp Features: alt-svc AsynchDNS HSTS HTTPS-proxy IPv6 Largefile libz SSL TLS-SRP UnixSockets I still see curl version is 7.88.1 and recommended fix is curl v8.4.0
  • s

    spp

    11/15/2023, 5:27 PM
    curl 7.88.1 is not vulnerable to CVE-2022-43552: https://nvd.nist.gov/vuln/detail/CVE-2022-43552. It is only known to affect below 7.87.0. There were recent curl CVEs CVE-2023-38545 and CVE-2023-38546. 38545 was patched in the most recent releases (7.27.0 and 8.3.1), although the curl package will still report as 7.88.1: https://www.puppet.com/docs/puppet/7/release_notes_puppet#security_puppet_x-7-27-0-PA-5848
  • s

    spp

    11/15/2023, 5:28 PM
    38546 will be patched in a future release, probably early 1Q2024.
  • a

    Anudeep Seri

    11/15/2023, 5:32 PM
    ok. will perform a scan check. Thanks for the response.
  • y

    Yadnyawalk Tale

    11/28/2023, 12:42 PM
    @spp do you know if puppet/puppet-agent was using OpenSSL SOCK5 proxy?
  • y

    Yadnyawalk Tale

    11/28/2023, 12:43 PM
    (I mean, I could see we have released fixes for CVE-2023-38545 in 7.27.0 but wanted to know if we were impacted)
  • s

    Slackbot

    11/28/2023, 1:50 PM
    This message was deleted.
    b
    s
    y
    • 4
    • 4
  • s

    Slackbot

    12/07/2023, 7:54 PM
    This message was deleted.
    b
    f
    • 3
    • 5
  • c

    Chris

    12/27/2023, 9:34 AM
    Hey! Does anyone have a strategy for renewing the hiera eyaml keypair? Do I really have to re-encrypt all the keys by hand?
  • c

    CVQuesty

    12/27/2023, 9:26 PM
    I mean, have one public and one private key on my Puppet server. I just generate new keys with the same name and move them into place. Should be a snap unless you created a ton of keys to all sorts of data points, then “yeah”, I think you’ll manually have to do that, but fortunately it’s only at the server.
    👍 1
  • h

    Hugo Haakseth

    02/22/2024, 8:16 AM
    https://github.com/advisories/GHSA-24rp-q3w6-vc56 I don't know Clojure, but it runs on jvm. Does anyone know if pgjdbc driver is in use?
    n
    • 2
    • 1
  • r

    rnelson0

    03/29/2024, 5:24 PM
    @rnelson0 has left the channel
  • o

    Oleksandr Lytvyn

    05/23/2024, 7:19 PM
    Hello, i've sent email to security@perforce.com about potential issue with Puppet Forge, in case of questions feel free to reach out to me
    âś… 1
    b
    d
    • 3
    • 30
  • c

    CVQuesty

    05/23/2024, 8:14 PM
    @binford2k
  • c

    CVQuesty

    11/26/2024, 7:35 PM
    @CVQuesty has left the channel
  • j

    jorhett

    01/15/2025, 10:21 PM
    Was there a change which prevents Puppet from writing out SSH keys to disk? I've got a situation that I've tested back and forth and sideways, and ANY content other than an OpenSSH private key ed25519 will write out to disk, but any OpenSSH key will write an empty file.
    b
    • 2
    • 14