Security advisory: Use of the 'port' parameter with puppetlabs-firewall could cause unexpectedly permissive firewall rules.

24 views
Skip to first unread message

Geoff Nichols

unread,
Aug 31, 2015, 2:50:41 PM8/31/15
to
Security advisory: Use of the 'port' parameter with puppetlabs-firewall could cause unexpectedly permissive firewall rules.

Assessed Risk Level: Medium

Previous versions of the README for the puppetlabs-firewall module contained examples of configurations using the 'port' parameter instead of referencing 'dport' and 'sport'. Following these examples explicitly could result in firewall rules that are unintentionally permissive. It is recommended to always use the specific 'dport' and 'sport' parameters.

With the puppetlabs-firewall 1.7.1 release, the 'port' parameter is now deprecated and will be removed in the next major release.

If any manifests using puppetlabs-firewall's firewall resource are configured to use the 'port' parameter, users should update those manifests to use the specific 'dport' or 'sport' parameters instead.



Geoff Nichols
Puppet Labs

PuppetConf 2015 is coming to Portland, Oregon! Join us October 5-9.
Register now to take advantage of the Final Countdown discount save $149!

Reply all
Reply to author
Forward
0 new messages