← Back

Continuous Delivery

continuous_delivery

Vendor: Puppet • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Puppet
1Continuous Delivery
Jun 17, 2026
Nov 18, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
1Puppet
1Continuous Delivery
Jun 17, 2026
Sep 18, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet E...Show more
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.Show less
1Puppet
1Continuous Delivery
Jun 17, 2026
Mar 26, 2020
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.
1Puppet
1Continuous Delivery
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have...Show more
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have been resolved in version 1.2.1 of the puppetlabs/cd4pe module.Show less