Posted: February 7, 2017
Assessed Risk Level: Medium
On January 17th, Oracle announced several security vulnerabilities in Java. Previous releases of Puppet Enterprise contained a vulnerable version of Java. Puppet Enterprise 2016.4.3 and 2016.5.2 contain an updated version of Java that has patched the vulnerabilities.
For more information about the Java vulnerabilities, refer to the Oracle security announcement.
Affected Software Versions:
- Puppet Enterprise prior to 2016.4.3
- Puppet Enterprise 2016.5.1
- Puppet Enterprise 2016.4.3
- Puppet Enterprise 2016.5.2