TROYANOSYVIRUS
Back to CVEs

CVE-2020-7945

MEDIUM
5.5

Description

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.

CVE Details

CVSS v3.1 Score5.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published9/18/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

puppet:continuous_delivery

Weaknesses (CWE)

CWE-522

References

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.