Versions of the puppetlabs-apache module prior to 1.11.1...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Sep 15, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 2, 2023
Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the
ssl_ca
parameter but do not specify thessl_certs_dir
parameter, a default will be provided for thessl_certs_dir
that will trust certificates from any of the system-trusted certificate authorities. This did not affect FreeBSD.References