CVE-2018-6517: Puppet Chloride
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride.
Affected products
- Puppet Chloride: before 0.3.0 (fixed in 0.3.0)
Published 2019-03-21. Last modified 2026-06-17.