« Volver al listado

CVE-2021-27026

Estado: ModificadaMedia (4.4)—

A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27026",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Puppet Enterprise, Puppet Connect",
          "versions": [
            {
              "status": "affected",
              "version": "Puppet Enterprise prior to 2019.8.9, Puppet Enterprise prior to 2021.4.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-18T15:15:09.560",
  "references": [
    {
      "url": "https://puppet.com/security/cve/cve-2021-27026",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "https://puppet.com/security/cve/cve-2021-27026",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged"
    },
    {
      "lang": "es",
      "value": "Se ha detectado un fallo en Puppet Enterprise y otros productos Puppet en el que es posible registrar parámetros confidenciales del plan."
    }
  ],
  "lastModified": "2026-06-17T03:44:09.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:puppet:puppet:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24089512-FFBB-4139-886F-571238403529",
              "versionEndExcluding": "2021.4.0",
              "versionStartIncluding": "2021.0.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppet_connect:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02E0DBA7-E86E-45DA-A06B-FA7211C9F7AF",
              "versionEndExcluding": "0.4.0"
            },
            {
              "criteria": "cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35844F76-3BBD-4C76-B24A-1B385AAE1AFC",
              "versionEndExcluding": "2019.8.9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@puppet.com"
}