Unsafe HTTP Redirect in Puppet Agent and Puppet Server
Moderate severity
GitHub Reviewed
Published
Dec 2, 2021
to the GitHub Advisory Database
•
Updated May 4, 2023
Package
Affected versions
>= 7.0.0, < 7.12.1
< 6.25.1
Patched versions
7.12.1
6.25.1
Description
Published by the National Vulnerability Database
Nov 18, 2021
Reviewed
Nov 30, 2021
Published to the GitHub Advisory Database
Dec 2, 2021
Last updated
May 4, 2023
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
References