CVE-2016-2785

CRITICAL

Puppet Server < 2.3.2 and Puppet 4.0.0-4.4.1 - Improper Access Control via URL Decoding Bypass

Title source: llm
STIX 2.1

Description

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://puppet.com/security/cve/cve-2016-2785
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201606-02

Scores

CVSS v3 9.8
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (20)
puppet/puppet 4.0.0 (4 CPE variants)
puppet/puppet 4.1.0
puppet/puppet 4.2.0
puppet/puppet 4.2.1
puppet/puppet 4.2.2
puppet/puppet 4.2.3
puppet/puppet 4.3.0
puppet/puppet 4.3.1
puppet/puppet 4.3.2
puppet/puppet 4.4.0
... and 10 more
Published Jun 10, 2016
Tracked Since Feb 18, 2026