In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-3765 In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: puppet

Published:

Updated: 2024-09-16T23:55:51.656Z

Reserved: 2018-06-05T00:00:00

Link: CVE-2018-11746

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-03T13:29:00.233

Modified: 2024-11-21T03:43:57.133

Link: CVE-2018-11746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.