CVE Vulnerabilities

CVE-2021-27022

Insertion of Sensitive Information into Log File

Published: Sep 07, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet2021.0.0 (including)2021.3.0 (excluding)
Puppet_enterprisePuppet*2019.8.8 (excluding)
PuppetUbuntubionic*
PuppetUbuntufocal*
PuppetUbuntuhirsute*
PuppetUbuntuimpish*
PuppetUbuntukinetic*
PuppetUbuntutrusty*
PuppetUbuntutrusty/esm*
PuppetUbuntuxenial*

Potential Mitigations

References