CVE-2016-2787
EUVD-2016-386013.02.2017, 18:59
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| puppet | puppet_enterprise | 2015.3.2 |
| puppetlabs | puppet_enterprise | 2015.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration