For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
History

Thu, 20 Nov 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Puppet puppet Enterprise
CPEs cpe:2.3:a:puppet:puppet:2023.3:*:*:*:enterprise:*:*:* cpe:2.3:a:puppet:puppet_enterprise:2023.3:*:*:*:*:*:*:*
Vendors & Products Puppet puppet
Puppet puppet Enterprise

Thu, 19 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: puppet

Published: 2023-10-03T17:54:55.177Z

Updated: 2024-09-19T19:29:30.230Z

Reserved: 2023-09-28T17:42:16.370Z

Link: CVE-2023-5255

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:08.537Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T18:15:10.577

Modified: 2025-11-20T18:30:37.727

Link: CVE-2023-5255

cve-icon Redhat

Severity : Low

Publid Date: 2023-10-03T00:00:00Z

Links: CVE-2023-5255 - Bugzilla