First published: Tue Jul 19 2022(Updated: )
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Perforce Puppet Bolt | <3.24.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2394 is a vulnerability in Puppet Bolt prior to version 3.24.0 that can result in sensitive parameters being logged when run programmatically.
CVE-2022-2394 affects Puppet Bolt versions prior to 3.24.0 and can result in sensitive parameters being printed when planning a run, potentially leading to them being logged when run programmatically.
The severity of CVE-2022-2394 is medium, with a severity value of 3.5.
To fix CVE-2022-2394, update Puppet Bolt to version 3.24.0 or higher.
More information about CVE-2022-2394 can be found at the following reference: [https://puppet.com/security/cve/CVE-2022-2394]