Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93j5-g845-9wqp

Опубликовано: 02 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Unsafe HTTP Redirect in Puppet Agent and Puppet Server

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

Пакеты

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

>= 7.0.0, < 7.12.1

7.12.1

Наименование

puppet

rubygems
Затронутые версииВерсия исправления

< 6.25.1

6.25.1

EPSS

Процентиль: 49%
0.00261
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

CVSS3: 9.8
redhat
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

CVSS3: 9.8
nvd
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

CVSS3: 9.8
debian
больше 3 лет назад

A flaw was discovered in Puppet Agent and Puppet Server that may resul ...

suse-cvrf
больше 2 лет назад

Security update for rubygem-puppet

EPSS

Процентиль: 49%
0.00261
Низкий

6.5 Medium

CVSS3