Security Advisory
CVE-2014-9355
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request information by leveraging access to an unspecified API endpoint.