ZeroHour

CVE-2017-2296

CVSS 3.0
6.5 medium
EPSS
<1%p57
Published
()
Modified
Description

In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.

Vendors
puppet
Products
puppet enterprise
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.