CVE-2018-11748: High severity puppet device manager vulnerability
Published Oct 2, 2018
·Updated
Previous releases of the Puppet devicemanager module creates configuration files containing credentials that are world readable. This issue has been resolved as of devicemanager 2.7.0.
Affected Software
1 affected component
Puppet Device Manager Puppet<2.7.0
Event History
Oct 2, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11748?
The severity of CVE-2018-11748 is high (7.8).
2
What is the affected software for CVE-2018-11748?
The affected software for CVE-2018-11748 is Puppet Device Manager up to version 2.7.0.
3
How can I resolve CVE-2018-11748?
To resolve CVE-2018-11748, update to version 2.7.0 or above of Puppet Device Manager.
4
What is the CWE ID for CVE-2018-11748?
The CWE ID for CVE-2018-11748 is 522.
5
Where can I find more information about CVE-2018-11748?
You can find more information about CVE-2018-11748 at the following link: [https://puppet.com/security/cve/CVE-2018-11748](https://puppet.com/security/cve/CVE-2018-11748)