PT-2018-7108 · Puppet · Puppet Enterprise
Published
2018-02-01
·
Updated
2022-01-24
·
CVE-2017-2296
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Puppet Enterprise versions 2017.1.x through 2017.2.1
Description:
The issue arises when specially formatted strings containing certain formatting characters are used as Classifier node group names or RBAC role display names, causing errors and effectively leading to a denial of service (DOS) to the service.
Recommendations:
For Puppet Enterprise versions 2017.1.x through 2017.2.1, update to version 2017.2.2 to resolve the issue.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Puppet Enterprise