CVE-2016-5716: Puppet Enterprise

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.

Affected products

  • Puppet Puppet Enterprise: version 2015.2.0 only; version 2015.2.1 only; version 2015.2.2 only; version 2015.2.3 only; version 2015.3.0 only; version 2015.3.1 only; …

Published 2017-08-09. Last modified 2026-06-17.