Bug 1212124 (CVE-2023-2530) - VUL-0: CVE-2023-2530: puppet: A privilege escalation allowing remote code execution was discovered in the orchestration service.
Summary: VUL-0: CVE-2023-2530: puppet: A privilege escalation allowing remote code exe...
Status: RESOLVED INVALID
Alias: CVE-2023-2530
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Danilo Spinella
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/368790/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-08 06:30 UTC by Gianluca Gabrielli
Modified: 2023-06-15 10:35 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gianluca Gabrielli 2023-06-08 06:30:53 UTC
A privilege escalation allowing remote code execution was discovered in the
orchestration service.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2530
https://www.cve.org/CVERecord?id=CVE-2023-2530
https://www.puppet.com/security/cve/cve-2023-2530-remote-code-execution-orchestrator
Comment 1 Gianluca Gabrielli 2023-06-08 06:36:52 UTC
Hi Danilo,

the puppet SA only mentions the following closed source products as affected:

 - Puppet Enterprise 2021.7.0 through Puppet Enterprise 2021.7.3 
 - Puppet Enterprise 2023.0 and Puppet Enterprise 2023.1

I found that orchestration features are only included in Puppet Enterprise. According to that, I'm kine to assess our maintained packages as not affected. Would you agree with that?

Packages we currently maintain:

 - SUSE:SLE-11-SP1:Update/puppet
 - SUSE:SLE-12:Update/puppet
Comment 2 Danilo Spinella 2023-06-15 08:52:21 UTC
(In reply to Gianluca Gabrielli from comment #1)
> Hi Danilo,
> 
> the puppet SA only mentions the following closed source products as affected:
> 
>  - Puppet Enterprise 2021.7.0 through Puppet Enterprise 2021.7.3 
>  - Puppet Enterprise 2023.0 and Puppet Enterprise 2023.1
> 
> I found that orchestration features are only included in Puppet Enterprise.
> According to that, I'm kine to assess our maintained packages as not
> affected. Would you agree with that?
> 
> Packages we currently maintain:
> 
>  - SUSE:SLE-11-SP1:Update/puppet
>  - SUSE:SLE-12:Update/puppet

Hello Gianluca, yes, I agree that SLE is not affected (especially considerinf that the version that are shipped are quite old).
Comment 3 Gianluca Gabrielli 2023-06-15 10:35:11 UTC
Thank you, closing.