Описание
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.24.0 (исключая)
cpe:2.3:a:perforce:puppet_bolt:*:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00253
Низкий
4.1 Medium
CVSS3
3.5 Low
CVSS3
Дефекты
CWE-200
CWE-532
Связанные уязвимости
CVSS3: 3.5
github
больше 3 лет назад
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
EPSS
Процентиль: 48%
0.00253
Низкий
4.1 Medium
CVSS3
3.5 Low
CVSS3
Дефекты
CWE-200
CWE-532