{"id":"CVE-2020-7942","aliases":["GHSA-gqvf-892r-vjm5"],"url":"https://o3.security/vulnerability/CVE-2020-7942","summary":"Improper Certificate Validation in Puppet","details":"Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Puppet 6.x prior to 6.13.0 Puppet Agent 6.x prior to 6.13.0 Puppet 5.5.x prior to 5.5.19 Puppet Agent 5.5.x prior to 5.5.19 Resolved in: Puppet 6.13.0 Puppet Agent 6.13.0 Puppet 5.5.19 Puppet Agent 5.5.19","published":"2020-02-19T21:15:11.747Z","modified":"2026-07-08T17:57:02.868673Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"puppet","fixedVersion":"6.13.0"},{"ecosystem":"RubyGems","name":"puppet","fixedVersion":"5.5.19"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://puppet.com/security/cve/CVE-2020-7942/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:57:02.868673Z"}}