CVE-2017-2297: High severity puppet enterprise vulnerability
Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issue has been fixed in Puppet Enterprise 2016.4.5 and 2017.2.1. This only affects users with labeled tokens, which is not the default for tokens.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2297?
CVE-2017-2297 is a vulnerability in Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 that allows unauthorized access to RBAC access tokens.
How severe is CVE-2017-2297?
CVE-2017-2297 has a severity rating of high (7.5).
Which versions of Puppet Enterprise are affected by CVE-2017-2297?
Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 are affected by CVE-2017-2297.
How can I fix CVE-2017-2297?
CVE-2017-2297 has been fixed in Puppet Enterprise 2016.4.5 and 2017.2.1, so it is recommended to upgrade to these versions.
Does CVE-2017-2297 affect all users?
No, CVE-2017-2297 only affects users with labeled tokens, which is not the default for tokens.