RubySec

Providing security resources for the Ruby community

CVE-2016-2785 (puppet): Puppet Improper Access Control

Puppet Improper Access Control

Published: April 26, 2016

SECURITY IDENTIFIERS

GEM

puppet

SEVERITY

CVSS v3.x: 9.8 (Critical)

CVSS v2.0: 7.5 (High)

PATCHED VERSIONS

>= 4.4.2

DESCRIPTION

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

RELATED