The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
{
"binaries": [
{
"binary_name": "puppet",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "puppet-common",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "puppet-el",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "puppet-testsuite",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "puppetmaster",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "puppetmaster-common",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "puppetmaster-passenger",
"binary_version": "3.4.3-1ubuntu1.3"
},
{
"binary_name": "vim-puppet",
"binary_version": "3.4.3-1ubuntu1.3"
}
]
}