PT-2022-16353 · Puppet · Puppet Bolt
Vadym Chepkov
·
Published
2022-07-19
·
Updated
2023-06-30
·
CVE-2022-2394
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Puppet Bolt versions prior to 3.24.0
Description
The issue allows sensitive parameters to be printed when planning a run, potentially resulting in them being logged when executed programmatically, such as through Puppet Enterprise.
Recommendations
For Puppet Bolt versions prior to 3.24.0, update to version 3.24.0 or later to resolve the issue. As a temporary workaround, consider restricting the logging of sensitive parameters when running Puppet Bolt programmatically until a patch is applied.
Fix
Information Disclosure
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Puppet Bolt