Bug 977471 (CVE-2016-2785) - VUL-0: CVE-2016-2785: puppet: incorrect URL decoding
Summary: VUL-0: CVE-2016-2785: puppet: incorrect URL decoding
Status: RESOLVED INVALID
Alias: CVE-2016-2785
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Kristyna Streitova
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/168348/
Whiteboard: CVSSv2:SUSE:CVE-2016-2785:3.5:(AV:N/...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-04-27 16:08 UTC by Andreas Stieger
Modified: 2016-05-24 11:06 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-04-27 16:08:24 UTC
https://puppet.com/security/cve/cve-2016-2785

 CVE-2016-2785 - Incorrect URL Decoding

    Posted April 26, 2016
    Assessed Risk Level: Low
    CVSS 3 Base Score: 3.5 AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Puppet Server 2.x and Ruby Puppet Master from Puppet 4.x did not correctly decode specific character combinations which could potentially allow for a host to access endpoints restricted by auth.conf rules.

This issue is fixed in Puppet Server 2.3.2, Puppet 4.4.2, and Puppet Agent 1.4.2.
Status:

Affected Software Versions:

    Puppet Server 2.x prior to 2.3.2
    Ruby puppetmaster in Puppet 4.x prior to Puppet 4.4.2
    Ruby puppetmaster in Puppet Agent prior to Puppet Agent 1.4.2

Resolved in:

    Puppet Server 2.3.2
    Puppet Agent 1.4.2
    Puppet 4.4.2


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1331024
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2785
Comment 1 Swamp Workflow Management 2016-04-27 22:04:33 UTC
bugbot adjusting priority
Comment 4 Andreas Stieger 2016-05-24 11:06:39 UTC
closing as not affecting us