Vulnerability Description
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Puppet | Puppet | >= 2021.0.0, < 2021.3.0 |
| Puppet | Puppet Enterprise | < 2019.8.8 |
Related Weaknesses (CWE)
References
- https://puppet.com/security/cve/cve-2021-27022/Vendor Advisory
- https://puppet.com/security/cve/cve-2021-27022/%5D
- https://puppet.com/security/cve/cve-2021-27022/Vendor Advisory
- https://puppet.com/security/cve/cve-2021-27022/%5D
FAQ
What is CVE-2021-27022?
CVE-2021-27022 is a vulnerability with a CVSS score of 4.9 (MEDIUM). A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinR...
How severe is CVE-2021-27022?
CVE-2021-27022 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27022?
Check the references section above for vendor advisories and patch information. Affected products include: Puppet Puppet, Puppet Puppet Enterprise.