A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2488 A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Github GHSA Github GHSA GHSA-93j5-g845-9wqp Unsafe HTTP Redirect in Puppet Agent and Puppet Server
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: puppet

Published:

Updated: 2024-08-03T20:40:47.068Z

Reserved: 2021-02-09T00:00:00

Link: CVE-2021-27023

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-18T15:15:09.273

Modified: 2024-11-21T05:57:11.907

Link: CVE-2021-27023

cve-icon Redhat

Severity : Important

Publid Date: 2021-11-09T00:00:00Z

Links: CVE-2021-27023 - Bugzilla

cve-icon OpenCVE Enrichment

No data.