CVE-2016-2787
13.02.2017, 18:59
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
puppet | puppet_enterprise | 2015.3.2 |
puppetlabs | puppet_enterprise | 2015.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration