Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3794-1

Опубликовано: 27 окт. 2022
Источник: suse-cvrf

Описание

Security update for rubygem-puppet

This update for rubygem-puppet fixes the following issues:

  • CVE-2021-27023: Fixed an unsafe HTTP redirect (bsc#1192797).

Список пакетов

SUSE Linux Enterprise Module for Advanced Systems Management 12
ruby2.1-rubygem-puppet-4.8.1-32.6.1
rubygem-puppet-4.8.1-32.6.1

Описание

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007


Затронутые продукты
SUSE Linux Enterprise Module for Advanced Systems Management 12:ruby2.1-rubygem-puppet-4.8.1-32.6.1
SUSE Linux Enterprise Module for Advanced Systems Management 12:rubygem-puppet-4.8.1-32.6.1

Ссылки