CVE-2021-27024: High severity puppet continuous delivery vulnerability
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27024?
CVE-2021-27024 is a vulnerability in Continuous Delivery for Puppet Enterprise (CD4PE) that allows a user with lower privileges to access a Puppet Enterprise API token.
What is the severity of CVE-2021-27024?
The severity of CVE-2021-27024 is high with a score of 8.1.
How does CVE-2021-27024 impact Puppet Continuous Delivery?
CVE-2021-27024 allows a user with lower privileges to access a Puppet Enterprise API token, potentially compromising the security of the system.
How can I fix CVE-2021-27024?
CVE-2021-27024 is resolved in CD4PE version 4.10.0, so updating to this version will fix the vulnerability.
Where can I find more information about CVE-2021-27024?
You can find more information about CVE-2021-27024 on the Puppet security website: https://puppet.com/security/cve/cve-2021-27024