CVE-2022-2394: Sensitive Parameter Exposure in Puppet Bolt prior to 3.24
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2394?
CVE-2022-2394 is a vulnerability in Puppet Bolt prior to version 3.24.0 that can result in sensitive parameters being logged when run programmatically.
How does CVE-2022-2394 affect Puppet Bolt?
CVE-2022-2394 affects Puppet Bolt versions prior to 3.24.0 and can result in sensitive parameters being printed when planning a run, potentially leading to them being logged when run programmatically.
What is the severity of CVE-2022-2394?
The severity of CVE-2022-2394 is medium, with a severity value of 3.5.
How can I fix CVE-2022-2394?
To fix CVE-2022-2394, update Puppet Bolt to version 3.24.0 or higher.
Where can I find more information about CVE-2022-2394?
More information about CVE-2022-2394 can be found at the following reference: [https://puppet.com/security/cve/CVE-2022-2394]