In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet Enterprise 2017.2.2.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: puppet

Published: 2018-02-01T22:00:00Z

Updated: 2024-09-17T03:48:29.424Z

Reserved: 2016-12-01T00:00:00

Link: CVE-2017-2296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-02-01T22:29:00.277

Modified: 2022-01-24T16:46:04.387

Link: CVE-2017-2296

cve-icon Redhat

No data.