Critical severity9.8NVD Advisory· Published Nov 18, 2021· Updated Jun 17, 2026
CVE-2021-27023
CVE-2021-27023
Description
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
puppetRubyGems | >= 7.0.0, < 7.12.1 | 7.12.1 |
puppetRubyGems | < 6.25.1 | 6.25.1 |
Affected products
8- osv-coords3 versionspkg:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012pkg:gem/puppetpkg:rpm/suse/rubygem-puppet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012
< 3.8.5-15.18.1+ 2 more
- (no CPE)range: < 3.8.5-15.18.1
- (no CPE)range: >= 7.0.0, < 7.12.1
- (no CPE)range: < 4.8.1-32.6.1
- cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*Range: <2019.8.9
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- Puppet/Agent and Serverdescription
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-93j5-g845-9wqpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-27023ghsaADVISORY
- puppet.com/security/cve/CVE-2021-27023nvdVendor AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2021-27023.ymlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62SELE7EKVKZL4GABFMVYMIIUZ7FPEF7/nvd
News mentions
0No linked articles in our index yet.