A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
2021-11-18T15:15:09.273
2024-11-21T05:57:11.907
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | puppet | puppet_agent | < 6.25.1 | Yes |
Application | puppet | puppet_agent | < 7.12.1 | Yes |
Application | puppet | puppet_enterprise | < 2019.8.9 | Yes |
Application | puppet | puppet_enterprise | < 2021.4 | Yes |
Application | puppet | puppet_server | < 6.17.1 | Yes |
Application | puppet | puppet_server | < 7.4.2 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |