CVE-2021-27019: Medium severity puppet enterprise vulnerability
Published Aug 30, 2021
·Updated
PuppetDB logging included potentially sensitive system information.
Affected Software
3 affected components
puppet Puppet Enterprise<2019.8.6
Puppet PuppetDB>=6.0.0<6.16.1
Puppet PuppetDB>=7.0.0<7.3.1
Event History
Aug 30, 2021
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-27019?
CVE-2021-27019 is a vulnerability where PuppetDB logging includes potentially sensitive system information.
2
How does CVE-2021-27019 affect Puppet Enterprise?
CVE-2021-27019 affects Puppet Enterprise versions up to and including 2019.8.6.
3
How does CVE-2021-27019 affect PuppetDB?
CVE-2021-27019 affects PuppetDB versions between 6.0.0 and 6.16.1, or between 7.0.0 and 7.3.1.
4
What is the severity of CVE-2021-27019?
CVE-2021-27019 has a severity rating of medium with a CVSS score of 4.3.
5
Where can I find more information about CVE-2021-27019?
More information about CVE-2021-27019 can be found at: https://puppet.com/security/cve/CVE-2021-27019