CRITICAL9.8
GHSA-pqj5-7r86-64fv
Puppet Improper Access Control
Quick fix
GHSA-pqj5-7r86-64fv — puppet: upgrade to the fixed version with the command below.
bundle update puppetDetails
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-2785[ADVISORY]
- https://github.com/puppetlabs/puppet/commit/6592a8166572e5f1b7d058474059b8519ec81387[WEB]
- https://github.com/puppetlabs/puppet[PACKAGE]
- https://github.com/puppetlabs/puppet/commits/4.4.2[WEB]
- https://puppet.com/security/cve/cve-2016-2785[WEB]
- https://security.gentoo.org/glsa/201606-02[WEB]