CVE-2016-5714: Puppet Agent
High severity, CVSS 7.2. EPSS: 2.2% chance of exploitation in the next 30 days.
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."
Affected products
- Puppet Puppet Agent: from 1.3.6, up to and including 1.7.0
- Puppet Puppet Enterprise: version 2015.3.3 only; version 2016.1.1 only; version 2016.1.2 only; version 2016.2.0 only; version 2016.2.1 only
Published 2017-10-18. Last modified 2026-06-17.