Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| puppet / puppet_enterprise | 3.0.1 | 3.0.1.x |
| puppet / puppet_enterprise | 3.0.0 | 3.0.0.x |
| puppet / puppet_enterprise | 3.1.0 | 3.1.0.x |
| puppet / puppet_enterprise | - | 3.1.1.x |