Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8804

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.

A flaw was found in Puppet resource_api. This vulnerability occurs because the resource-api does not properly preserve the sensitive flag on parameters. As a result, sensitive information, such as passwords, can be stored in cleartext within the agent's local transaction state cache. This could allow an attacker with access to the agent's cache to retrieve sensitive data.

Отчет

Red Hat OpenStack Platform 17.1 ships rubygem-puppet-resource_api version 1.8.13, which is within the affected range (1.5.0-1.9.1). Red Hat Satellite ships puppet-agent which bundles the resource_api gem; investigation is ongoing to determine if those versions are in the affected range. The sensitive flag on resource_api parameters is not properly preserved, causing values such as passwords to be stored in cleartext in the Puppet agent's local transaction state cache.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 17.1rubygem-puppet-resource_apiFix deferred
Red Hat Satellite 6puppet-agentFix deferred
Red Hat Satellite 6satellite-capsule:el8/puppet-agentFix deferred
Red Hat Satellite 6satellite:el8/puppet-agentFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-256
https://bugzilla.redhat.com/show_bug.cgi?id=2496777resource_api: Puppet Core: Puppet Enterprise: Puppet resource_api: Cleartext storage of sensitive information due to improper flag preservation

EPSS

Процентиль: 0%
0.00082
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.

nvd
около 1 месяца назад

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.

debian
около 1 месяца назад

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise ...

github
около 1 месяца назад

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.

EPSS

Процентиль: 0%
0.00082
Низкий

4.4 Medium

CVSS3