CVE-2018-11749 Vulnerability Details

  /     /     /  

CVE-2018-11749 Metadata Quick Info

CVE Published: 24/08/2018 | CVE Updated: 16/09/2024 | CVE Year: 2018
Source: puppet | Vendor: Puppet | Product: Puppet Enterprise
Status : PUBLISHED

CVE-2018-11749 Description

When users are configured to use startTLS with RBAC LDAP, at login time, the user\'s credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper Authentication
Source: Puppet

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).