Back

CRITICAL

puppet: incorrect URL decoding

Published Jun 10, 2016

Description

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of Puppet as shipped with various Red Hat products as they did not include support Puppet 3.x (using Passenger 4.x).

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 10, 2016
Updated Aug 5, 2024
Reserved Feb 29, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 26, 2016
GHSA-PQJ5-7R86-64FV