Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://puppetlabs.com/security/cve/cve-2015-7330 | vendor advisory |
http://www.securitytracker.com/id/1034550 | vdb entry third party advisory |