Описание
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.10.0 (исключая)
cpe:2.3:a:puppet:continuous_delivery:*:*:*:*:puppet_enterprise:*:*:*
EPSS
Процентиль: 54%
0.00317
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
EPSS
Процентиль: 54%
0.00317
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-Other