Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h2m-rx7g-r9gv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.

EPSS

Процентиль: 61%
0.0042
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.

EPSS

Процентиль: 61%
0.0042
Низкий

Дефекты

CWE-798