Sensitive Parameter Exposure in Puppet Bolt prior to 3.24
Vulnerability Description
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2394
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Thanks to Vadym Chepkov for the report
More from Puppet
View All →Affected Vendor
Puppet
View all reports →