CVE-2016-5716: High severity puppet enterprise vulnerability
Published Aug 9, 2017
·Updated
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
Affected Software
12 affected components
puppet Puppet Enterprise=2015.2.0
puppet Puppet Enterprise=2015.2.1
puppet Puppet Enterprise=2015.2.2
puppet Puppet Enterprise=2015.2.3
puppet Puppet Enterprise=2015.3.0
puppet Puppet Enterprise=2015.3.1
puppet Puppet Enterprise=2015.3.2
puppet Puppet Enterprise=2015.3.3
puppet Puppet Enterprise=2016.1.1
puppet Puppet Enterprise=2016.1.2
puppet Puppet Enterprise=2016.2.0
puppet Puppet Enterprise=2016.2.1
Event History
Aug 9, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5716?
CVE-2016-5716 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2016-5716?
To fix CVE-2016-5716, update Puppet Enterprise to version 2016.4.0 or later.
3
Which versions of Puppet Enterprise are affected by CVE-2016-5716?
Puppet Enterprise versions 2015.x and 2016.x prior to 2016.4.0 are affected by CVE-2016-5716.
4
What kind of vulnerability is CVE-2016-5716?
CVE-2016-5716 is a remote code execution vulnerability due to unsafe string reads in the Puppet Enterprise console.
5
Is there any workaround for CVE-2016-5716?
There are no recommended workarounds for CVE-2016-5716; updating to a secure version is essential.