CVE-2015-7330: High severity puppet enterprise vulnerability
Published Apr 11, 2016
·Updated
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol.
Affected Software
1 affected component
puppet Puppet Enterprise=2015.3.0
Event History
Apr 11, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7330?
CVE-2015-7330 has a medium severity rating due to the potential for remote exploitation.
2
How do I fix CVE-2015-7330?
To fix CVE-2015-7330, upgrade to Puppet Enterprise version 2015.3.1 or later.
3
What vulnerability does CVE-2015-7330 address?
CVE-2015-7330 addresses a vulnerability that allows attackers to bypass host whitelist protections.
4
Who is affected by CVE-2015-7330?
CVE-2015-7330 affects Puppet Enterprise 2015.3.0 and earlier versions.
5
What impact does CVE-2015-7330 have on systems?
The impact of CVE-2015-7330 includes unauthorized actions due to the bypass of security mechanisms.