CVSS 3 Base Score:

Posted On:

Assessed Risk Level:
Low

In October, the PostgreSQL project announced several security vulnerabilities in the PostgreSQL database server. Puppet Enterprise versions prior to 2015.2.3 contained affected versions of PostgreSQL. Puppet Enterprise 3.8.3 and 2015.2.3 contain updated PostgreSQL packages that address the vulnerabilities. For more information about the PostgreSQL vulnerabilities, refer to the PostgreSQL security announcement.

Status:

Affected software versions:
  • Puppet Enterprise 3.x
  • Puppet enterprise 2015.2.x
Resolved in:
  • Puppet Enterprise 3.8.3
  • Puppet Enterprise 2015.2.3