RSS   Vulnerabilities for 'Continuous delivery'   RSS

2021-11-18
 
CVE-2021-27024

CWE-732
 

 
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0

 
2020-03-26
 
CVE-2020-7944

CWE-200
 

 
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.

 
2019-12-12
 
CVE-2019-10695

CWE-532
 

 
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user?s username and password were exposed in the job?s Job Details pane in the PE console. These issues have been resolved in version 1.2.1 of the puppetlabs/cd4pe module.

 

 >>> Vendor: Puppet 19 Products
Puppet
Mcollective
Enterprise
Puppetlabs-apache
Chloride
Puppet enterprise
Puppet dashboard
Hiera
Marionette collective
Puppet server
Stdlib
Facter
Discovery
Puppet agent
Continuous delivery
Puppetdb
Remediate
Puppet connect
Firewall


Copyright 2024, cxsecurity.com

 

Back to Top