Lucene search

K
cvelistPuppetCVELIST:CVE-2021-27022
HistorySep 07, 2021 - 1:03 p.m.

CVE-2021-27022

2021-09-0713:03:48
CWE-532
puppet
www.cve.org
1

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).

CNA Affected

[
  {
    "product": "Puppet Enterprise",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "2019.8.7"
      }
    ]
  }
]

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Related for CVELIST:CVE-2021-27022