CVSS 3 Base Score: Posted On: June 23, 2020Assessed Risk Level: MediumOn January 9, 2020, NGINX published CVE-2019-20372 addressing HTTP request smuggling. Previous releases of Puppet Enterprise contain a vulnerable version of nginx. Puppet Enterprise versions 2019.8.0 and 2018.1.16 contain an updated version of nginx that has patched the vulnerabilities.For more information about these vulnerabilities, refer to the NGINX security announcement .Status:Affected software versions:Puppet Enterprise versions prior to 2019.8.0Puppet Enterprise versions prior to 2018.1.16Resolved in:Puppet Enterprise 2019.8.0Puppet Enterprise 2018.1.16← Back to CVE Listings