CVE-2018-11751: Puppet Server
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.
Affected products
- Puppet Puppet Server: from 6.0.0, before 6.4.0 (fixed in 6.4.0)
Published 2019-12-16. Last modified 2026-06-17.