The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
{ "binaries": [ { "binary_name": "puppet", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "puppet-common", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "puppet-el", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "puppet-testsuite", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "puppetmaster", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "puppetmaster-common", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "puppetmaster-passenger", "binary_version": "3.4.3-1ubuntu1.3" }, { "binary_name": "vim-puppet", "binary_version": "3.4.3-1ubuntu1.3" } ] }