Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: puppet
Published: 2020-09-18T17:58:51
Updated: 2024-08-04T09:48:24.936Z
Reserved: 2020-01-23T00:00:00
Link: CVE-2020-7945
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-18T18:15:20.287
Modified: 2024-11-21T05:38:03.890
Link: CVE-2020-7945
Redhat