First published: Wed Dec 11 2019(Updated: )
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have been resolved in version 1.2.1 of the puppetlabs/cd4pe module.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Continuous Delivery | <1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10695 is a vulnerability that exposes the root user's username and password in the Job Details pane of the PE console when using the cd4pe::root_configuration task in a Continuous Delivery for PE installation.
CVE-2019-10695 has a severity rating of medium.
You can fix CVE-2019-10695 by upgrading to version 1.2.1 of the puppetlabs/cd4pe module.
Versions up to but not including 1.2.1 of the puppetlabs/cd4pe module are affected by CVE-2019-10695.
Yes, you can find more information about CVE-2019-10695 at https://puppet.com/security/cve/CVE-2019-10695.