RSS   Vulnerabilities for 'Continuous delivery'   RSS

2021-11-18
 
CVE-2021-27024

CWE-732
 

 
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0

 
2020-03-26
 
CVE-2020-7944

CWE-200
 

 
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.

 
2019-12-12
 
CVE-2019-10695

CWE-532
 

 
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user?s username and password were exposed in the job?s Job Details pane in the PE console. These issues have been resolved in version 1.2.1 of the puppetlabs/cd4pe module.

 

 >>> Vendor: Puppet 19 Products
Discovery
Enterprise
Firewall
Puppet
Puppet enterprise
Puppet dashboard
Mcollective
Facter
Hiera
Puppet server
Stdlib
Puppet agent
Puppetlabs-apache
Chloride
Marionette collective
Continuous delivery
Puppetdb
Remediate
Puppet connect


Copyright 2024, cxsecurity.com

 

Back to Top