CVE

Id
89604  
CVE No.
CVE-2016-2785  
Status
Candidate  
Description
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.  
Phase
Assigned (20160229)  
Votes
None (candidate not yet proposed)  
Comments