FreeBSD : mcollective -- cert valication issue (ecea9e92-0be5-4931-88da-8772d044972a)
Medium Nessus Plugin ID 76630
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionMelissa Stone reports :
The MCollective aes_security public key plugin does not correctly validate certs against the CA. By exploiting this vulnerability within a race/initialization window, an attacker with local access could initiate an unauthorized MCollective client connection with a server, and thus control the mcollective plugins running on that server. This vulnerability requires a collective be configured to use the aes_security plugin. Puppet Enterprise and open source MCollective are not configured to use the plugin and are not vulnerable by default.
SolutionUpdate the affected package.