CVE-2020-7944: Infoleak
Published Mar 26, 2020
·Updated
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.
Affected Software
1 affected component
Puppet Continuous Delivery Puppet Enterprise<3.4.0
Event History
Mar 26, 2020
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-7944.
2
What is the severity of CVE-2020-7944?
The severity of CVE-2020-7944 is high, with a value of 7.7.
3
What software is affected by CVE-2020-7944?
Continuous Delivery for Puppet Enterprise (CD4PE) before version 3.4.0 is affected by CVE-2020-7944.
4
What is the impact of CVE-2020-7944?
Changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.
5
How can I fix CVE-2020-7944?
To fix CVE-2020-7944, upgrade to version 3.4.0 or later of Continuous Delivery for Puppet Enterprise (CD4PE).