VDB
Sign up
MEDIUM6.5

GHSA-93j5-g845-9wqp

Unsafe HTTP Redirect in Puppet Agent and Puppet Server

Quick fix

GHSA-93j5-g845-9wqp — puppet: upgrade to the fixed version with the command below.

bundle update puppet

Details

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/puppet
Introduced in: 7.0.0Fixed in: 7.12.1
Fixbundle update puppet
RubyGems/puppet
Introduced in: 0Fixed in: 6.25.1
Fixbundle update puppet

References