RubySec

Providing security resources for the Ruby community

CVE-2016-2785 (puppet): Puppet Improper Access Control

ADVISORIES

GEM

puppet

SEVERITY

CVSS v3.x: 9.8 (Critical)

CVSS v2.0: 7.5 (High)

PATCHED VERSIONS

  • >= 4.4.2

DESCRIPTION

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

RELATED