VDB
Sign up
MEDIUM

GHSA-9pvx-fwwh-w289

Puppet does not properly restrict access to node resources

Quick fix

GHSA-9pvx-fwwh-w289 — puppet: upgrade to the fixed version with the command below.

bundle update puppet

Details

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/puppet
Introduced in: 2.6.0Fixed in: 2.6.4
Fixbundle update puppet

References