On October 15th, the OpenSSL project announced several security vulnerabilities in OpenSSL. Puppet Enterprise versions prior to 3.7.0 contained vulnerable versions of OpenSSL. Puppet Enterprise 3.7 contains updated versions of OpenSSL that have patched the vulnerabilities.
For more information about the OpenSSL vulnerabilities, refer to the OpenSSL security announcement.
Affected Software Versions:
- Puppet Enterprise 2.x
- Puppet Enterprise 3.x