CVE-2017-2296
published 2018-02-01CVE-2017-2296: In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role…
PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
0.88%
56.6th percentile
In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cc93-3xjh-46wh: In Puppet Enterprise 2017
ghsa_unreviewed·2022-05-13
CVE-2017-2296 [MEDIUM] CWE-20 GHSA-cc93-3xjh-46wh: In Puppet Enterprise 2017
In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.
Debian
CVE-2017-2296: puppet - In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings wi...
vendor_debian·2017·CVSS 6.5
CVE-2017-2296 [MEDIUM] CVE-2017-2296: puppet - In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings wi...
In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-01
Published