CVE Database
/

CVE-2021-27023

Back to search

CVE-2021-27023

Published: Nov 18, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

VendorProductVersions

n/a

Puppet Enterprise, Puppet Server, Puppet Agent

affected
Puppet Enterprise prior to 2019.8.9, Puppet Enterprise prior to 2021.4, Puppet Server prior to 6.17.1, Puppet Server prior to 7.4.2, Puppet Agent prior to 6.25.1, Puppet Agent prior to 7.12.1

References

FEDORA-2021-1c0e788093
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now