Posted August 8, 2017
Assessed Risk Level: Medium
On July 18th, Oracle announced several security vulnerabilities in Java. Previous releases of Puppet Enterprise contain a vulnerable version of Java. Puppet Enterprise 2016.4.7 and 2017.2.3 contain an updated version of Java that has patched the vulnerabilities.
For more information about the Java vulnerabilities, refer to the Oracle security announcement.
Affected Software Versions:
- Puppet Enterprise prior to 2016.4.7
- Puppet Enterprise 2017.1.x
- Puppet Enterprise 2017.2.x prior to 2017.2.3
- Puppet Enterprise 2016.4.7
- Puppet Enterprise 2017.2.3