Puppet Enterprise 2015.3 contained a misconfiguration in which non-whitelisted hosts were permitted to communicate over the Puppet communications protocol and potentially control Puppet.
This issue is fixed in 2015.3.1.
Affected Software Versions:
Resolved in: