CVE-2021-27023
published 2021-11-18CVE-2021-27023: A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.33%
67.9th percentile
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| debian | puppet-agent | — | — |
| debian | puppetserver | — | — |
| fedoraproject | fedora | — | — |
| puppet | puppet | >= 0 < 6.25.1 | 6.25.1 |
| puppet | puppet | >= 7.0.0 < 7.12.1 | 7.12.1 |
| puppet | puppet_agent | < 6.25.1 | 6.25.1 |
| puppet | puppet_agent | >= 7.0.0 < 7.12.1 | 7.12.1 |
| puppet | puppet_enterprise | < 2019.8.9 | 2019.8.9 |
| puppet | puppet_enterprise | >= 2021.0.0 < 2021.4 | 2021.4 |
| puppet | puppet_server | < 6.17.1 | 6.17.1 |
| puppet | puppet_server | >= 7.0.0 < 7.4.2 | 7.4.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
ghsa·2021-12-02·CVSS 9.8
CVE-2021-27023 [CRITICAL] Unsafe HTTP Redirect in Puppet Agent and Puppet Server
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
OSV
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
osv·2021-12-02·CVSS 9.8
CVE-2021-27023 [CRITICAL] Unsafe HTTP Redirect in Puppet Agent and Puppet Server
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
OSV
CVE-2021-27023: A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different hos
osv·2021-11-18·CVSS 9.8
CVE-2021-27023 [CRITICAL] CVE-2021-27023: A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different hos
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Red Hat
puppet: unsafe HTTP redirect
vendor_redhat·2021-11-09·CVSS 9.8
CVE-2021-27023 [CRITICAL] CWE-200 puppet: unsafe HTTP redirect
puppet: unsafe HTTP redirect
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
An exposure flaw was found in Puppet Agent and Puppet Server where HTTP credentials were leaked. When the HTTP redirects occurred, the authentication and cookie header was added when following redirects to a different host. This flaw allows an unauthorized network attacker to access sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.
Statement: Red Hat Satellite 6.8 and earlier versions are not affected by this vulnerability.
Package: puppet (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: puppet (Red Hat
Debian
CVE-2021-27023: puppet - A flaw was discovered in Puppet Agent and Puppet Server that may result in a lea...
vendor_debian·2021·CVSS 9.8
CVE-2021-27023 [CRITICAL] CVE-2021-27023: puppet - A flaw was discovered in Puppet Agent and Puppet Server that may result in a lea...
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Scope: local
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/https://puppet.com/security/cve/CVE-2021-27023https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/https://puppet.com/security/cve/CVE-2021-27023
2021-11-18
Published