Impact
The Puppet resource_api module loses the memory of the sensitive flag on parameters created through the resource-api, causing data such as passwords to be written in cache. The stored secrets are therefore exposed to anyone who can read the cache, directly risking the compromise of credentials used by the system.
Affected Systems
This flaw affects Perforce Puppet Core 8.x and Perforce Puppet Enterprise 2023.8.x and 2025.x. Versions of the resource_api module between 1.5.0 and 1.9.1, as well as version 2.0.0, are vulnerable. The issue is remedied in resource_api 1.9.2 and 2.0.1, which are included in Puppet Core 8.20.0, PE 2023.8.10, and PE 2025.11.0.
Risk and Exploitability
With a CVSS score of 6.7 the vulnerability represents moderate severity. EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is inferred from the description to be local access to the agent's transaction state cache, though a remote adversary who can compromise the agent could also gain read access. The consequence is the exposure of password or other sensitive data contained in or unauthorized access to downstream services.
OpenCVE Enrichment