CVE-2021-27026: Medium severity puppet vulnerability
Published Nov 18, 2021
·Updated
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
Affected Software
3 affected components
Puppet Puppet>=2021.0.0<2021.4.0
Puppet Puppet Connect<0.4.0
Puppet Puppet Enterprise<2019.8.9
Event History
Nov 18, 2021
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27026?
The severity of CVE-2021-27026 is medium.
2
Which Puppet products are affected by CVE-2021-27026?
Puppet Enterprise, Puppet Connect, and Puppet Enterprise are affected by CVE-2021-27026.
3
What is the vulnerability description of CVE-2021-27026?
CVE-2021-27026 is a vulnerability in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged.
4
How can CVE-2021-27026 be fixed?
CVE-2021-27026 can be fixed by updating Puppet Enterprise to version 2021.4.0 or higher, Puppet Connect to version 0.4.1 or higher, and Puppet Enterprise to version 2019.8.10 or higher.
5
Where can I find more information about CVE-2021-27026?
More information about CVE-2021-27026 can be found at https://puppet.com/security/cve/cve-2021-27026.