VDB
Sign up
CRITICAL9.8

GHSA-pqj5-7r86-64fv

Puppet Improper Access Control

Quick fix

GHSA-pqj5-7r86-64fv — puppet: upgrade to the fixed version with the command below.

bundle update puppet

Details

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/puppet
Introduced in: 4.0.0Fixed in: 4.4.2
Fixbundle update puppet

References