Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://puppet.com/security/cve/CVE-2022-2394 | release notes vendor advisory |