CVE-2015-4100: Puppet Enterprise
Medium severity, CVSS 6.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."
Affected products
- Puppet Puppet Enterprise: from 3.7.0, up to and including 3.7.2; version 3.8.0 only
Published 2017-12-21. Last modified 2026-06-17.