First published: Fri Sep 18 2020(Updated: )
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Continuous Delivery | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7945 is a vulnerability in Continuous Delivery for Puppet Enterprise (CD4PE) where local registry credentials were included directly in the deployment definition, potentially exposing them to unauthorized users.
CVE-2020-7945 has a severity value of 5.5 (Medium).
You can fix CVE-2020-7945 by upgrading to Continuous Delivery for Puppet Enterprise 4.0.1.