A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://puppet.com/security/cve/cve-2021-27022/%5D | |
https://puppet.com/security/cve/cve-2021-27022/ | vendor advisory |