CVE-2018-11746
03.07.2018, 13:29
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.Enginsight
Vendor | Product | Version |
---|---|---|
puppet | discovery | 𝑥 < 1.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References