
CVE-2016-5715 – Puppet Enterprise Web Interface Open Redirect
https://notcve.org/view.php?id=CVE-2016-5715
22 Oct 2016 — Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6501. La vulnerabilidad de redirección abierta en la Consola en Puppet Enterprise 2015.x y 2016.x en versiones anteriores a 2016.4.0 permite a atacantes remotos redirigir a lo... • https://packetstorm.news/files/id/139302 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2016-2786 – Gentoo Linux Security Advisory 201606-02
https://notcve.org/view.php?id=CVE-2016-2786
06 Jun 2016 — The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate. El componente pxp-agent en Puppet Enterprise 2015.3.x en versiones anteriores a 2015.3.3 y Puppet Agent 1.3.x en versiones anteriores a 1.3.6 no valida adecuadamente certificados de servidor, lo que podría permitir a atacantes remotos espiar broker... • https://puppet.com/security/cve/CVE-2016-2786 • CWE-20: Improper Input Validation •

CVE-2015-7330
https://notcve.org/view.php?id=CVE-2015-7330
11 Apr 2016 — Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol. Puppet Enterprise 2015.3 en versiones anteriores a 2015.3.1 permite a atacantes remotos eludir un mecanismo de protección de lista blanca de host aprovechándose del protocolo de comunicaciones Puppet. • http://www.securitytracker.com/id/1034550 • CWE-254: 7PK - Security Features •