CVE-2017-2293Enterprise vulnerability

4 documents4 sources
Severity
4.9MEDIUMNVD
EPSS
0.2%
top 54.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 1
Latest updateMay 13

Description

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who rely on this functionality can change this policy.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDpuppet/puppet_enterprise< 2016.4.5+4
CVEListV5puppet/puppet_enterpriseprior to 2016.4.5, 2016.5.x, 2017.1.x, resolved in 2016.4.5 and 2017.2.1

🔴Vulnerability Details

2
GHSA
GHSA-wg8j-wm67-mv7w: Versions of Puppet Enterprise prior to 20162022-05-13
CVEList
CVE-2017-2293: Versions of Puppet Enterprise prior to 20162018-02-01

📋Vendor Advisories

1
Debian
CVE-2017-2293: puppet - Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCol...2017
CVE-2017-2293 — Puppet Enterprise vulnerability | cvebase