ALASEMR-PUPPET-2023-001


Amazon Linux 2 Security Advisory: ALASEMR-PUPPET-2023-001
Advisory Release Date: 2023-09-06 19:00 Pacific
Advisory Updated Date: 2023-09-25 22:13 Pacific
Severity: Medium

Issue Overview:

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. (CVE-2021-27025)


Affected Packages:

emr-puppet


Note:

This advisory is applicable to Amazon Linux 2 - Emr-puppet Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update emr-puppet to update your system.

New Packages:
noarch:
    emr-puppet-6.17.0-1.amzn2.0.3.noarch

src:
    emr-puppet-6.17.0-1.amzn2.0.3.src