CVSS 3 Base Score:

Posted On:

Assessed Risk Level:
Medium

Previous releases of Puppet Enterprise contain a vulnerable version of Rack. Puppet Enterprise 2018.1.12, 2019.1.4, and 2019.3.0 contain an updated version of Rack that has patched the vulnerabilities.

For more information about this vulnerability, refer to the [National Vulnerability Database](https://nvd.nist.gov/vuln/detail/CVE-2019-16782).https://nvd.nist.gov/vuln/detail/CVE-2019-16782

Status:

Affected software versions:
  • Puppet Enterprise versions prior to 2018.1.12
  • Puppet Enterprise versions prior to 2019.1.4
  • Puppet Enterprise versions prior to 2019.3.0
Resolved in:
  • Puppet Enterprise 2018.1.12
  • Puppet Enterprise 2019.1.4
  • Puppet Enterprise 2019.3.0