Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
2022-07-19T18:15:11.563
2024-11-21T07:00:54.223
Modified
CVSSv3.1: 4.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | perforce | puppet_bolt | < 3.24.0 | Yes |