CVE-2018-11746
EUVD-2018-376503.07.2018, 13:29
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| puppet | discovery | 𝑥 < 1.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References