SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7945

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them.

MEDIUM 5.5EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.31% probability · 23th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
puppet/continuous delivery
Source
security@puppet.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.