First published: Thu Nov 18 2021(Updated: )
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Continuous Delivery | <4.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27024 is a vulnerability in Continuous Delivery for Puppet Enterprise (CD4PE) that allows a user with lower privileges to access a Puppet Enterprise API token.
The severity of CVE-2021-27024 is high with a score of 8.1.
CVE-2021-27024 allows a user with lower privileges to access a Puppet Enterprise API token, potentially compromising the security of the system.
CVE-2021-27024 is resolved in CD4PE version 4.10.0, so updating to this version will fix the vulnerability.
You can find more information about CVE-2021-27024 on the Puppet security website: https://puppet.com/security/cve/cve-2021-27024