For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
The product does not release or incorrectly releases a resource before it is made available for re-use.
Link | Tags |
---|---|
https://www.puppet.com/security/cve/cve-2023-5255-denial-service-revocation-auto-renewed-certificates | vendor advisory |