CVE-2018-11748

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
02/10/2018
Last modified:
03/10/2019

Description

Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:puppet:device_manager:*:*:*:*:*:puppet:*:* 2.7.0 (excluding)


References to Advisories, Solutions, and Tools