First published: Thu Nov 18 2021(Updated: )
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Puppet | >=2021.0.0<2021.4.0 | |
Puppet Puppet Connect | <0.4.0 | |
Puppet Puppet Enterprise | <2019.8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27026 is medium.
Puppet Enterprise, Puppet Connect, and Puppet Enterprise are affected by CVE-2021-27026.
CVE-2021-27026 is a vulnerability in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged.
CVE-2021-27026 can be fixed by updating Puppet Enterprise to version 2021.4.0 or higher, Puppet Connect to version 0.4.1 or higher, and Puppet Enterprise to version 2019.8.10 or higher.
More information about CVE-2021-27026 can be found at https://puppet.com/security/cve/cve-2021-27026.