Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2016-06-10T15:00:00

Updated: 2024-08-05T23:32:21.089Z

Reserved: 2016-02-29T00:00:00

Link: CVE-2016-2785

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-06-10T15:59:00.140

Modified: 2021-09-09T12:56:50.293

Link: CVE-2016-2785

cve-icon Redhat

Severity : Low

Publid Date: 2016-04-26T00:00:00Z

Links: CVE-2016-2785 - Bugzilla