CVE-2018-6517: Puppet Chloride

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride.

Affected products

  • Puppet Chloride: before 0.3.0 (fixed in 0.3.0)

Published 2019-03-21. Last modified 2026-06-17.