CVSS 3 Base Score:

Posted On:

Assessed Risk Level:
High

On July 14th 2020, Oracle announced several security vulnerabilities in Java. Previous releases of Puppet Enterprise contain a vulnerable version of Java. Puppet Enterprise 2018.1.16 and 2019.8.1 contain an updated version of Java that has patched the vulnerabilities.

For more information about these Java vulnerabilities, refer to the security announcement.

Status:

Affected software versions:
  • Puppet Enterprise versions prior to 2018.1.16
  • Puppet Enterprise versions prior to 2019.8.1
Resolved in:
  • Puppet Enterprise 2018.1.16
  • Puppet Enterprise 2019.8.1