CVE-2018-6517 describes a vulnerability in puppet chloride versions prior to 0.3.0, where the application would automatically add host fingerprints for unknown hosts to the user's known_hosts file without confirmation. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity that could lead to high integrity impact, specifically the unauthorized modification of the known_hosts file. While the vulnerability is significant, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding it. The issue has been addressed in chloride version 0.3.0, which no longer updates the known_hosts file.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.0CPE matchmatch criteria | cpe:2.3:a:puppet:chloride:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.