4
CVSSv2

CVE-2017-2296

Published: 01/02/2018 Updated: 24/01/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2017.1.0

puppet puppet enterprise 2017.2.1

puppet puppet enterprise 2017.1.1