CVE-2018-11746
Puppet Discovery can leak authentication information
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
Puppet · Puppet DiscoveryWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →