CVE-2017-2296: Input Validation
In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2296?
CVE-2017-2296 is a vulnerability in Puppet Enterprise 2017.1.x and 2017.2.1 that allows specially formatted strings to cause errors and cause a Denial-of-Service (DoS) to the service.
How does CVE-2017-2296 affect Puppet Enterprise?
CVE-2017-2296 affects Puppet Enterprise 2017.1.x and 2017.2.1, causing a Denial-of-Service (DoS) to the service when certain formatting characters are used as Classifier node group names or RBAC role display names.
How severe is CVE-2017-2296?
CVE-2017-2296 has a severity rating of 6.5 (Medium).
How can I fix CVE-2017-2296?
To fix CVE-2017-2296, update Puppet Enterprise to version 2017.2.2 or later.
Is there any additional information about CVE-2017-2296?
For additional information about CVE-2017-2296, you can refer to the official Puppet security advisory at https://puppet.com/security/cve/cve-2017-2296.