A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| puppet(RubyGems) | 7.0.0 | 7.12.1 | N/A |
| puppet(RubyGems) | 0 | 6.25.1 | N/A |
CVSS Metrics